Description
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions.
Published: 2026-08-19
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated Cross Site Scripting flaw exists in versions of the WordPress Contest Gallery plugin through 30.0.5. The flaw allows an attacker to inject arbitrary client‑side script into the gallery pages, leading to potential cookie theft, credential hijacking, or execution of malicious code in the context of visitors to the affected site. This vulnerability is identified as CWE-79.

Affected Systems

The issue affects the WordPress Contest Gallery plugin released by Wasiliy Strecker. All plugin releases up to and including version 30.0.5 are vulnerable. Users of WordPress sites that have installed any of these versions must examine their installations for the presence of the Contest Gallery plugin.

Risk and Exploitability

The CVSS base score of 7.1 indicates a high potential impact, ranking the vulnerability as High. The EPSS score of 0.00146 indicates a very low probability of exploitation, though the lack of a public exploit suggests the risk remains moderate. The plugin does not require authentication to be abused, making the attack vector likely to be unauthenticated through a crafted URL or form submission. Because the flaw has not been reported in the CISA Known Exploited Vulnerabilities list, no current exploitation campaigns are known, but sites that expose the plugin remain susceptible to XSS‑mediated compromise.

Generated by OpenCVE AI on August 20, 2026 at 18:25 UTC.

Remediation

Vendor Solution

Update the WordPress Contest Gallery Plugin to the latest available version (at least 30.0.6).


OpenCVE Recommended Actions

  • Update the WordPress Contest Gallery Plugin to version 30.0.6 or later.
  • If updating immediately is not possible, remove the Contest Gallery Plugin or disable it until the patch is applied.
  • Implement input sanitization or Web Application Firewall rules to filter out script payloads in future if the plugin remains installed.

Generated by OpenCVE AI on August 20, 2026 at 18:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Wasiliy Strecker
Wasiliy Strecker contest Gallery
Wordpress
Wordpress wordpress
Vendors & Products Wasiliy Strecker
Wasiliy Strecker contest Gallery
Wordpress
Wordpress wordpress

Wed, 19 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions.
Title WordPress Contest Gallery plugin <= 30.0.5 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wasiliy Strecker Contest Gallery
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-19T15:37:14.491Z

Reserved: 2026-07-13T06:14:00.716Z

Link: CVE-2026-61986

cve-icon Vulnrichment

Updated: 2026-08-19T15:37:10.397Z

cve-icon NVD

Status : Deferred

Published: 2026-08-19T13:17:49.090

Modified: 2026-08-20T12:49:04.990

Link: CVE-2026-61986

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T18:30:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')