CVE 4.3 MEDIUM

Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.3 - Unauthenticated CSV Injection_CVE-2025-11254

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Description

The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 27.0.3 via gallery submissions. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.

Basic Information

ID CVE-2025-11254
Source Wordfence
Published Oct 11, 2025 at 08:29

Affected Product

Vendor contest-gallery
Product Contest Gallery – Upload, Vote & Sell with PayPal and Stripe
Version *
Affected Versions contest-gallery Contest Gallery – Upload, Vote & Sell with PayPal and Stripe *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.