The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 27.0.3 via gallery submissions. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
Metrics
Affected Vendors & Products
References
History
Tue, 14 Oct 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 11 Oct 2025 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 27.0.3 via gallery submissions. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration. | |
Title | Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.3 - Unauthenticated CSV Injection | |
Weaknesses | CWE-1236 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-10-11T08:29:16.424Z
Updated: 2025-10-14T14:11:30.733Z
Reserved: 2025-10-03T11:57:16.168Z
Link: CVE-2025-11254

Updated: 2025-10-14T13:30:51.991Z

Status : Awaiting Analysis
Published: 2025-10-11T09:15:32.453
Modified: 2025-10-14T19:36:59.730
Link: CVE-2025-11254

No data.