The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 27.0.3 via gallery submissions. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
                
            Metrics
Affected Vendors & Products
References
        History
                    Mon, 20 Oct 2025 16:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Contest-gallery Contest-gallery contest Gallery Wordpress Wordpress wordpress | |
| Vendors & Products | Contest-gallery Contest-gallery contest Gallery Wordpress Wordpress wordpress | 
Tue, 14 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Sat, 11 Oct 2025 08:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 27.0.3 via gallery submissions. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration. | |
| Title | Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.3 - Unauthenticated CSV Injection | |
| Weaknesses | CWE-1236 | |
| References |  | 
 | 
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: Wordfence
Published: 2025-10-11T08:29:16.424Z
Updated: 2025-10-14T14:11:30.733Z
Reserved: 2025-10-03T11:57:16.168Z
Link: CVE-2025-11254
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-10-14T13:30:51.991Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-10-11T09:15:32.453
Modified: 2025-10-14T19:36:59.730
Link: CVE-2025-11254
 Redhat
                        Redhat
                    No data.