Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Elymaro

#51807of 53,630
4.3Total CVSS
Vulnerabilities · 1
PT-2025-41648
4.3
2025-10-11
WordPress · Contest Gallery · CVE-2025-11254
**Name of the Vulnerable Software and Affected Versions** The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress versions prior to 27.0.4 **Description** The software is susceptible to CSV Injection through gallery submissions. This allows unauthenticated attackers to embed untrusted input into exported CSV files. Opening these files on a local system with a vulnerable configuration can lead to code execution. **Recommendations** Update to version 27.0.4 or later.