Impact
The Contest Gallery WordPress plugin fails to enforce a capability check or verify a nonce in the post_cg_get_openai_prompts handler. As a result, any authenticated user with the Subscriber role can request the endpoint and retrieve the entire stored OpenAI prompt history. This disclosure can expose sensitive user prompts, internal usage patterns, or private data that was submitted to the plugin and is stored on the site.
Affected Systems
Any WordPress site that has the Contest Gallery plugin installed and running a version earlier than 30.0.7 is affected. The plugin is listed as covering an unknown vendor named Contest Gallery, so all installations that match that product name and version range require review.
Risk and Exploitability
The vulnerability is exploitable by any Subscriber‑level user who can log into the site. No additional privilege escalation is required, so the attack vector is local authenticated access. CVSS and EPSS scores are not provided in the CVE record, and the vulnerability is not listed in the CISA KEV catalog. The absence of a non‑ce strictly increases the risk for broad user pools, but the attack remains confined to authenticated users on the affected WordPress site.
OpenCVE Enrichment