
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25035 is an Authentication Bypass Using an Alternate Path or Channel vulnerability (CWE-288) in the WordPress Contest Gallery plugin, developed by Wasiliy Strecker / ContestGallery developer. It allows unauthenticated remote attackers to circumvent authentication controls and potentially achieve account takeover on affected WordPress sites. All versions of the plugin through 28.1.2.2 are affected; version 28.1.3 contains the fix. The vulnerability was reported on January 13, 2026, and publicly disclosed on March 23–25, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) (Patchstack, Feedly).
The vulnerability is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), meaning the plugin exposes an alternate code path or channel that bypasses its normal authentication enforcement. An unauthenticated network attacker can exploit this without any user interaction or special privileges, by abusing contest-related functionality that should be restricted to higher-privileged users. The flaw is categorized under OWASP Top 10 A7: Identification and Authentication Failures. The vulnerability was discovered by researcher 'daroo' and reported through Patchstack's Active VDP program (Patchstack).
Successful exploitation allows an unauthenticated attacker to bypass login controls and perform actions normally restricted to privileged users, potentially gaining administrative access to the WordPress site. Concrete impacts include unauthorized access to sensitive data, manipulation of contest entries, account takeover, and compromise of overall application integrity. Given the CVSS score of 9.8, the vulnerability poses critical risk to confidentiality, integrity, and availability of affected WordPress installations (Patchstack, Feedly).
There is currently no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.024% (0.000240), indicating a low current probability of exploitation in the near term. However, Patchstack notes that vulnerabilities with a CVSS score of 9.8 are frequently targeted in mass-exploit campaigns against WordPress plugins, regardless of site traffic or popularity. No threat actor attribution has been reported at this time (Patchstack).
The patched version is Contest Gallery 28.1.3, which resolves the authentication bypass. Site administrators should update the plugin immediately to version 28.1.3 or later. As a temporary measure if patching is not immediately possible, Patchstack has issued a virtual patch (mitigation rule) for its users to block exploitation attempts. Additionally, administrators should implement network-level access controls to restrict unauthorized access to Contest Gallery endpoints and monitor application logs for suspicious or anomalous authentication attempts (Patchstack).
Wordfence included CVE-2026-25035 in its weekly WordPress vulnerability report covering March 23–29, 2026, highlighting it as a notable authentication issue in the WordPress plugin ecosystem (Wordfence). Patchstack, which coordinated the disclosure, classified it as high priority and emphasized the risk of mass-exploit campaigns targeting such vulnerabilities. No significant broader media coverage or notable researcher commentary beyond these security vendor reports has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."