
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24964 is a Server-Side Request Forgery (SSRF) vulnerability in the WordPress Contest Gallery plugin developed by Wasiliy Strecker / ContestGallery developer. It affects all versions of the plugin up to and including 28.1.2.1, and was discovered and reported by researcher lilmingwa13 on December 9, 2025, with public disclosure on March 10, 2026. The vulnerability carries a CVSS v3.1 base score of 6.4 (Medium) (Patchstack, Feedly).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery) and maps to CAPEC-664. An authenticated attacker with at minimum Subscriber-level privileges can craft malicious requests that cause the Contest Gallery plugin to issue server-side HTTP requests to arbitrary domains or internal network endpoints controlled by the attacker. The changed scope (S:C) in the CVSS vector indicates that the impact extends beyond the vulnerable component itself, potentially reaching internal services and infrastructure not directly accessible from the internet (Patchstack, Feedly).
Successful exploitation allows an attacker to force the WordPress server to make requests to arbitrary internal or external URLs, potentially exposing sensitive information from internal services, cloud metadata endpoints (e.g., AWS IMDSv1), or other backend systems not publicly accessible. The confidentiality and integrity impacts are rated Low in the CVSS scoring, reflecting the ability to read and potentially influence internal service responses. This vulnerability could be leveraged to enumerate internal network topology, harvest cloud credentials, or pivot to other internal services (Patchstack).
Exploitation requires a low level of privilege (Subscriber role or higher) and no user interaction, with low attack complexity over a network vector, making it accessible to a broad range of attackers. The EPSS score is approximately 0.017% (0.000170), indicating a currently low probability of exploitation in the wild. No public proof-of-concept exploit code, active in-the-wild exploitation, or CISA KEV catalog listing has been identified for this CVE at this time. Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack, Feedly).
inurl:/wp-content/plugins/contest-gallery/).http://169.254.169.254/latest/meta-data/ (AWS metadata) or http://localhost/admin/ to probe internal services.netstat/ss output.The vendor has released version 28.1.2.2 of the Contest Gallery plugin, which patches this vulnerability. Site administrators should update to version 28.1.2.2 or later immediately via the WordPress plugin dashboard. Patchstack users benefit from a virtual patching/mitigation rule that blocks exploitation attempts until the plugin is updated. If immediate updating is not possible, consider restricting Subscriber-level user registration or temporarily deactivating the plugin (Patchstack).
The vulnerability was reported through Patchstack's Active Vulnerability Disclosure Program (VDP) and was included in Wordfence's weekly WordPress vulnerability report for the week of March 9–15, 2026. No significant broader media coverage or notable researcher commentary beyond the initial disclosure has been identified (Wordfence, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."