CVE-2026-24964: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-24964 is a Server-Side Request Forgery (SSRF) vulnerability in the WordPress Contest Gallery plugin developed by Wasiliy Strecker / ContestGallery developer. It affects all versions of the plugin up to and including 28.1.2.1, and was discovered and reported by researcher lilmingwa13 on December 9, 2025, with public disclosure on March 10, 2026. The vulnerability carries a CVSS v3.1 base score of 6.4 (Medium) (Patchstack, Feedly).

Technical details

The vulnerability is classified as CWE-918 (Server-Side Request Forgery) and maps to CAPEC-664. An authenticated attacker with at minimum Subscriber-level privileges can craft malicious requests that cause the Contest Gallery plugin to issue server-side HTTP requests to arbitrary domains or internal network endpoints controlled by the attacker. The changed scope (S:C) in the CVSS vector indicates that the impact extends beyond the vulnerable component itself, potentially reaching internal services and infrastructure not directly accessible from the internet (Patchstack, Feedly).

Impact

Successful exploitation allows an attacker to force the WordPress server to make requests to arbitrary internal or external URLs, potentially exposing sensitive information from internal services, cloud metadata endpoints (e.g., AWS IMDSv1), or other backend systems not publicly accessible. The confidentiality and integrity impacts are rated Low in the CVSS scoring, reflecting the ability to read and potentially influence internal service responses. This vulnerability could be leveraged to enumerate internal network topology, harvest cloud credentials, or pivot to other internal services (Patchstack).

Exploitability

Exploitation requires a low level of privilege (Subscriber role or higher) and no user interaction, with low attack complexity over a network vector, making it accessible to a broad range of attackers. The EPSS score is approximately 0.017% (0.000170), indicating a currently low probability of exploitation in the wild. No public proof-of-concept exploit code, active in-the-wild exploitation, or CISA KEV catalog listing has been identified for this CVE at this time. Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack, Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Contest Gallery plugin version 28.1.2.1 or earlier using tools like WPScan, Shodan, or Google dorks (e.g., inurl:/wp-content/plugins/contest-gallery/).
  2. Obtain low-privilege access: Register or obtain a Subscriber-level account on the target WordPress site, as the vulnerability requires at minimum this privilege level.
  3. Identify the vulnerable endpoint: Locate the Contest Gallery plugin functionality that accepts user-supplied URLs or external resource references (e.g., image import or gallery source fields).
  4. Craft SSRF payload: Submit a request to the vulnerable endpoint with a crafted URL pointing to an internal resource, such as http://169.254.169.254/latest/meta-data/ (AWS metadata) or http://localhost/admin/ to probe internal services.
  5. Retrieve response: Observe the server's response or error messages to extract sensitive information from internal services, cloud metadata endpoints, or internal network hosts not directly accessible from the internet (Patchstack).

Indicators of compromise

  • Network: Outbound HTTP/HTTPS requests from the WordPress server to internal IP ranges (e.g., 169.254.169.254, 10.x.x.x, 172.16.x.x, 192.168.x.x) or unexpected external domains originating from the web server process.
  • Logs: WordPress or web server access logs showing authenticated requests to Contest Gallery plugin endpoints with unusual URL parameters pointing to internal addresses or cloud metadata endpoints; repeated requests to the same internal endpoint from a single low-privilege user account.
  • Process: Web server process (e.g., Apache, Nginx, PHP-FPM) initiating unexpected outbound connections to non-standard destinations, observable via network monitoring or netstat/ss output.

Mitigation and workarounds

The vendor has released version 28.1.2.2 of the Contest Gallery plugin, which patches this vulnerability. Site administrators should update to version 28.1.2.2 or later immediately via the WordPress plugin dashboard. Patchstack users benefit from a virtual patching/mitigation rule that blocks exploitation attempts until the plugin is updated. If immediate updating is not possible, consider restricting Subscriber-level user registration or temporarily deactivating the plugin (Patchstack).

Community reactions

The vulnerability was reported through Patchstack's Active Vulnerability Disclosure Program (VDP) and was included in Wordfence's weekly WordPress vulnerability report for the week of March 9–15, 2026. No significant broader media coverage or notable researcher commentary beyond the initial disclosure has been identified (Wordfence, Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management