Impact
The Contest Gallery WordPress plugin contains a stored cross‑site scripting flaw that allows attackers to inject arbitrary scripts into pages rendered for other users. Those scripts run in the victim's browser, enabling theft of session cookies, defacement, or redirect to malicious sites. The CVSS score of 7.1 reflects a high impact on confidentiality and integrity of victim users.
Affected Systems
WordPress plugin Contest Gallery by Wasiliy Strecker/Contest Gallery developer is affected in all releases through version 26.0.6, including 26.0.6 and previous builds. No specific patch versions are listed, but the issue applies to every installation of the plugin up to and including the stated 26.0.6.
Risk and Exploitability
The vulnerability can be exploited from the web interface where users submit contest entries or other content that is stored and later displayed. An attacker with the ability to create or modify such input can embed malicious code, and the analysis infers that it would likely require an authenticated user with content‑submission privileges, but this is not explicitly stated. The EPSS score of <1% and absence from CISA KEV indicate a low likelihood of widespread exploitation at present, though the threat remains significant for sites with public or high‑privilege content creation.
OpenCVE Enrichment
EUVD