---
id: CVE-2026-78088
title: >-
  The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe
  plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite
  in all versions up to, and including, 32.0.1 due to insufficient file path
  valida…
summary: >-
  The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe
  plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite
  in all versions up to, and including, 32.0.1 due to insufficient file path
  valida…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
vendor: contest-gallery
product: 'Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe'
affected:
  - contest_gallery_upload_vote_photos_media_sell_with_paypal_stripe <= 32.0.1
published: '2026-09-16'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:17:39.820'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78088'
references:
  - url: >-
      https://plugins.trac.wordpress.org/changeset?old_path=/contest-gallery/tags/32.0.1/v10/v10-admin/gallery/change-gallery/1_content-fb-like.php&new_path=/contest-gallery/tags/33.0.0/v10/v10-admin/gallery/change-gallery/1_content-fb-like.php
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/af2115ba-5573-41ce-8d5a-58c57c65c75a?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-16T03:49:03.878Z'
epss: 0.00786
epssPercentile: 0.54194
---

## Overview

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path validation in the 'baseUrlForFacebook' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite known files which may lead to remote code execution when certain preconditions are met.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
