Impact
The vulnerability is a missing authorization flaw that allows attackers to perform actions normally restricted to authorized users within the Contest Gallery plugin. It can lead to the unauthorized retrieval or manipulation of contest entries, potentially exposing sensitive user data or altering contest results. The weakness is categorized as CWE-862, indicating a lack of proper access control enforcement.
Affected Systems
WordPress sites utilizing the Contest Gallery plugin from any version up to and including 28.1.1 are affected. The plugin is developed by Wasiliy Strecker / Contest Gallery. No minimum affected version is specified, so any installation prior to 28.1.2 may be vulnerable.
Risk and Exploitability
The CVSS score of 4.3 places this issue in the moderate severity range, and the EPSS score of less than 1% suggests a low but non‑zero likelihood of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely through web requests targeting plugin endpoints that should enforce administrator privileges. If the plugin’s access controls are misconfigured, an unauthenticated attacker may also gain elevated access. The overall risk is moderate, but organizations running affected versions should consider remediation promptly.
OpenCVE Enrichment