Impact
The vulnerability is an unauthenticated Cross Site Scripting flaw in Contest Gallery plugin versions up to 30.0.6. It permits attackers to inject malicious scripts that execute in the browsers of unsuspecting visitors, leading to possible session hijacking, data theft, or defacement. The weakness is a classic scripting injection (CWE‑79).
Affected Systems
Affected products include the WordPress Contest Gallery plugin authored by Wasiliy Strecker. Any WordPress instance running Contest Gallery 30.0.6 or older is susceptible. No further vendor or product variants are listed.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity impact. The EPSS score is < 1% and the vulnerability is not currently listed in the CISA KEV catalog. The flaw is unauthenticated, meaning a remote attacker can target anyone who views a gallery page. An attacker could insert JavaScript into gallery content and compromise visitors browsing the site. Because the vector is client‑side, the likelihood of exploitation depends on site traffic and user engagement.
OpenCVE Enrichment