{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/contest-gallery/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:contestgallery:contest_gallery:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-78088"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Contest Gallery (\u003c= 32.0.1)"],"_cs_severities":["high"],"_cs_tags":["wordpress","vulnerability","rce"],"_cs_type":"advisory","_cs_vendors":["Contest Gallery"],"content_html":"\u003cp\u003eThe Contest Gallery WordPress plugin is affected by a critical vulnerability, tracked as CVE-2026-78088, which enables arbitrary file overwrite. The flaw resides in the 'baseUrlForFacebook' parameter, which lacks sufficient validation. While initially described as unauthenticated, the vulnerability can be leveraged by any attacker with subscriber-level access or higher to overwrite arbitrary files on the underlying web server. By overwriting critical PHP files or configuration files, an attacker can facilitate remote code execution (RCE). This vulnerability affects all versions of the plugin up to and including 32.0.1. Defenders should treat this as a high-priority risk for any WordPress site utilizing this plugin, as it provides a direct pathway for full site compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an attacker to overwrite sensitive files within the WordPress installation directory. This can lead to the execution of arbitrary code with the privileges of the web server user, resulting in full site takeover, data exfiltration, or the deployment of persistent backdoors. The scope of impact is limited to WordPress installations running the affected plugin versions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Contest Gallery plugin to the latest available patched version immediately.\u003c/li\u003e\n\u003cli\u003eAudit the WordPress installation directory for unauthorized changes to core files, particularly following any suspicious login activity.\u003c/li\u003e\n\u003cli\u003eRestrict file system write permissions for the web server user to only those directories strictly required for operation, such as the /uploads folder.\u003c/li\u003e\n\u003cli\u003eMonitor web access logs for requests containing unexpected directory traversal characters or malicious payloads targeting the 'baseUrlForFacebook' parameter.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T05:46:39Z","date_published":"2026-09-16T05:46:39Z","id":"https://feed.craftedsignal.io/briefs/2026-09-contest-gallery-overwrite/","summary":"The Contest Gallery WordPress plugin is vulnerable to unauthenticated arbitrary file overwrite via the 'baseUrlForFacebook' parameter, allowing authenticated attackers to achieve remote code execution.","title":"Arbitrary File Overwrite in Contest Gallery WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-contest-gallery-overwrite/"}],"language":"en","title":"CraftedSignal Threat Feed - Contest Gallery","version":"https://jsonfeed.org/version/1.1"}