<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Contest Gallery (&lt;= 32.0.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/contest-gallery--32.0.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 05:46:39 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/contest-gallery--32.0.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary File Overwrite in Contest Gallery WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-contest-gallery-overwrite/</link><pubDate>Wed, 16 Sep 2026 05:46:39 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-contest-gallery-overwrite/</guid><description>The Contest Gallery WordPress plugin is vulnerable to unauthenticated arbitrary file overwrite via the 'baseUrlForFacebook' parameter, allowing authenticated attackers to achieve remote code execution.</description><content:encoded><![CDATA[<p>The Contest Gallery WordPress plugin is affected by a critical vulnerability, tracked as CVE-2026-78088, which enables arbitrary file overwrite. The flaw resides in the 'baseUrlForFacebook' parameter, which lacks sufficient validation. While initially described as unauthenticated, the vulnerability can be leveraged by any attacker with subscriber-level access or higher to overwrite arbitrary files on the underlying web server. By overwriting critical PHP files or configuration files, an attacker can facilitate remote code execution (RCE). This vulnerability affects all versions of the plugin up to and including 32.0.1. Defenders should treat this as a high-priority risk for any WordPress site utilizing this plugin, as it provides a direct pathway for full site compromise.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows an attacker to overwrite sensitive files within the WordPress installation directory. This can lead to the execution of arbitrary code with the privileges of the web server user, resulting in full site takeover, data exfiltration, or the deployment of persistent backdoors. The scope of impact is limited to WordPress installations running the affected plugin versions.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the Contest Gallery plugin to the latest available patched version immediately.</li>
<li>Audit the WordPress installation directory for unauthorized changes to core files, particularly following any suspicious login activity.</li>
<li>Restrict file system write permissions for the web server user to only those directories strictly required for operation, such as the /uploads folder.</li>
<li>Monitor web access logs for requests containing unexpected directory traversal characters or malicious payloads targeting the 'baseUrlForFacebook' parameter.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>vulnerability</category><category>rce</category></item></channel></rss>