CVE-2026-25035: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-25035 is an Authentication Bypass Using an Alternate Path or Channel vulnerability (CWE-288) in the WordPress Contest Gallery plugin, developed by Wasiliy Strecker / ContestGallery developer. It allows unauthenticated remote attackers to circumvent authentication controls and potentially achieve account takeover on affected WordPress sites. All versions of the plugin through 28.1.2.2 are affected; version 28.1.3 contains the fix. The vulnerability was reported on January 13, 2026, and publicly disclosed on March 23–25, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) (Patchstack, Feedly).

Technical details

The vulnerability is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), meaning the plugin exposes an alternate code path or channel that bypasses its normal authentication enforcement. An unauthenticated network attacker can exploit this without any user interaction or special privileges, by abusing contest-related functionality that should be restricted to higher-privileged users. The flaw is categorized under OWASP Top 10 A7: Identification and Authentication Failures. The vulnerability was discovered by researcher 'daroo' and reported through Patchstack's Active VDP program (Patchstack).

Impact

Successful exploitation allows an unauthenticated attacker to bypass login controls and perform actions normally restricted to privileged users, potentially gaining administrative access to the WordPress site. Concrete impacts include unauthorized access to sensitive data, manipulation of contest entries, account takeover, and compromise of overall application integrity. Given the CVSS score of 9.8, the vulnerability poses critical risk to confidentiality, integrity, and availability of affected WordPress installations (Patchstack, Feedly).

Exploitability

There is currently no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.024% (0.000240), indicating a low current probability of exploitation in the near term. However, Patchstack notes that vulnerabilities with a CVSS score of 9.8 are frequently targeted in mass-exploit campaigns against WordPress plugins, regardless of site traffic or popularity. No threat actor attribution has been reported at this time (Patchstack).

Mitigation and workarounds

The patched version is Contest Gallery 28.1.3, which resolves the authentication bypass. Site administrators should update the plugin immediately to version 28.1.3 or later. As a temporary measure if patching is not immediately possible, Patchstack has issued a virtual patch (mitigation rule) for its users to block exploitation attempts. Additionally, administrators should implement network-level access controls to restrict unauthorized access to Contest Gallery endpoints and monitor application logs for suspicious or anomalous authentication attempts (Patchstack).

Community reactions

Wordfence included CVE-2026-25035 in its weekly WordPress vulnerability report covering March 23–29, 2026, highlighting it as a notable authentication issue in the WordPress plugin ecosystem (Wordfence). Patchstack, which coordinated the disclosure, classified it as high priority and emphasized the risk of mass-exploit campaigns targeting such vulnerabilities. No significant broader media coverage or notable researcher commentary beyond these security vendor reports has been identified.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management