CVE-2026-78088
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path validation in the 'baseUrlForFacebook' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite known files which may lead to remote code execution when certain preconditions are met.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.60%
- CWE
- CWE-434
- Published
- 2026-09-16
- Last modified
- 2026-09-16
Affected products
- contest-gallery Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe
Weakness type
Related vulnerabilities
- CVE-2026-56291 — Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1
- CVE-2026-75949 — Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3
- CVE-2026-74803 — Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64
- CVE-2026-57827 — Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
- CVE-2026-84147 — Remote Code Execution Vulnerability in Manacle Technologies ERP System
- CVE-2026-82970 — WordPress WP Cookie Notice for GDPR, CCPA & ePrivacy Consent plugin <= 4.4.1 - Arbitrary File Upload vulnerability
- CVE-2026-81780 — WordPress Hash Form plugin <= 1.4.2 - Arbitrary File Upload vulnerability
- CVE-2026-66665 — WordPress Type Hub plugin <= 2.0.6 - Arbitrary File Upload vulnerability