Impact
The Contest Gallery WordPress plugin allows an attacker to overwrite files through the baseUrlForFacebook parameter because the code does not validate the file path. An authenticated user with subscriber-level privileges or higher can supply a crafted value that will overwrite a specified file on the server. If the overwritten file is a PHP script or another executable component, the attacker can run arbitrary code, which is the primary concern identified as a Remote Code Execution vulnerability and aligns with CWE‑434.
Affected Systems
All releases of Contest Gallery up to and including version 32.0.1 are vulnerable. The plugin is used to upload and vote photos, distribute media, and manage e‑commerce payments via PayPal and Stripe on WordPress sites. Site administrators who have installed any of these affected versions are exposed if they have not applied the 33.0.0 update that sanitizes the baseUrlForFacebook parameter.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while an EPSS score of less than 1 % suggests that exploitation is currently unlikely but not impossible. The vulnerability is not listed in CISA’s KEV catalog. Attackers must first obtain a subscriber-level or higher authenticated session, which is the main prerequisite for exploitation. Once authenticated, a malformed baseUrlForFacebook payload can overwrite critical files, potentially resulting in remote code execution if the overwritten file is subsequently executed by the web server.
OpenCVE Enrichment