Impact
The Contest Gallery WordPress plugin implements a handler named post_cg_get_openai_prompts that does not perform a capability or nonce check. Consequently, any authenticated user with a Subscriber role can trigger the handler and retrieve the full history of OpenAI prompts stored by the plugin. This allows disclosure of potentially sensitive user input, internal usage patterns, or private data kept on the site.
Affected Systems
Any WordPress installation that has the Contest Gallery plugin version earlier than 30.0.7 is affected. The plugin is identified by the vendor name Contest Gallery; therefore, sites running this plugin prior to the specified version should be reviewed and assessed for exposure.
Risk and Exploitability
The vulnerability is exploitable using only local authenticated access; any user who can log in as a Subscriber can read the prompt history. No privilege escalation is necessary. The CVSS score of 4.3 indicates low severity, the EPSS score of <1% reflects a low probability of exploitation, and the issue is not listed in the CISA KEV catalog.
OpenCVE Enrichment