PT-2025-47044 · WordPress · Contest Gallery

Published

2025-11-15

·

Updated

2025-11-15

·

CVE-2025-12849

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Contest Gallery plugin for WordPress versions up to and including 28.0.2
Description The Contest Gallery plugin for WordPress is susceptible to authorization bypass. The plugin registers the cg check wp admin upload v10 AJAX action for both authenticated and unauthenticated users without capability checks or nonce verification. This allows unauthenticated attackers to inject arbitrary WordPress media attachments into galleries and manipulate gallery metadata via the cg check wp admin upload v10 action. The issue does not allow attackers to move or upload files.
Recommendations Update the Contest Gallery plugin to a version later than 28.0.2.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-12849

Affected Products

Contest Gallery