Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Plugin for WordPress, CVE-2026-24965
- CVE, Research URL
- Application
- Published on
- Feb 03, 2026
- Research Description
- Missing Authorization vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contest Gallery: from n/a through <= 28.1.1.
- Affected versions
-
max 28.1.1.
- Status
-
vulnerable
| Previous vulnerability researches |
|---|
| YITH PayPal Express Checkout for WooCommerce (CVE-2019-16251) , Jun 07, 2024 |
| YITH PayPal Express Checkout for WooCommerce (CVE-2025-48111) , Jun 18, 2025 |