Impact
The Contest Gallery WordPress plugin as deployed before version 30.0.7 does not use the standard WordPress authentication mechanism. After a password check it issues an authentication cookie directly, bypassing any brute‑force protection and two‑factor‑authentication that might be installed on the site. Because of this bypass, an attacker can perform unlimited, unthrottled password guessing against any user account, including administrators, and eventually gain full account takeover.
Affected Systems
All installations of the Contest Gallery WordPress plugin that are running a version older than 30.0.7. The vendor is an unknown organization hosting the plugin under the name 'Contest Gallery'.
Risk and Exploitability
The vulnerability allows an attacker to bypass authentication safeguards and take over accounts. The CVSS score is not provided in the CVE entry. EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. Nonetheless, because the plugin does not enforce login throttling and two‑factor authentication, the risk of exploitation is high, particularly for sites where the plugin is enabled and the default WordPress login protection is not configured.
OpenCVE Enrichment