Impact
An unauthenticated Cross Site Scripting flaw exists in versions of the WordPress Contest Gallery plugin through 30.0.5. The flaw allows an attacker to inject arbitrary client‑side script into the gallery pages, leading to potential cookie theft, credential hijacking, or execution of malicious code in the context of visitors to the affected site. This vulnerability is identified as CWE-79.
Affected Systems
The issue affects the WordPress Contest Gallery plugin released by Wasiliy Strecker. All plugin releases up to and including version 30.0.5 are vulnerable. Users of WordPress sites that have installed any of these versions must examine their installations for the presence of the Contest Gallery plugin.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high potential impact, ranking the vulnerability as High. The EPSS score of 0.00146 indicates a very low probability of exploitation, though the lack of a public exploit suggests the risk remains moderate. The plugin does not require authentication to be abused, making the attack vector likely to be unauthenticated through a crafted URL or form submission. Because the flaw has not been reported in the CISA Known Exploited Vulnerabilities list, no current exploitation campaigns are known, but sites that expose the plugin remain susceptible to XSS‑mediated compromise.
OpenCVE Enrichment