CVE-2026-42660
Description
Sensitive data exposure in WordPress Contest Gallery plugin up to version 28.1.7 allows subscribers to view private data; update to 29.0.0 to fix.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Sensitive data exposure in WordPress Contest Gallery plugin up to version 28.1.7 allows subscribers to view private data; update to 29.0.0 to fix.
Vulnerability
The WordPress Contest Gallery plugin, versions 28.1.7 and earlier, contains a sensitive data exposure vulnerability. Subscriber-level authenticated users can access private information that should be restricted. The issue resides in insufficient access controls for certain data endpoints [1].
Exploitation
An attacker needs a subscriber-level account on the target WordPress site. By exploiting the plugin's improper data access controls, the attacker can retrieve sensitive information intended for other user roles or for administrators only. No special privileges beyond subscriber are required [1].
Impact
Successful exploitation allows an attacker to view sensitive data, potentially including personal information of other users or private application data. This leads to unauthorized information disclosure with a CVSS score of 6.5 (Medium) and is expected to be used in mass exploitation campaigns [1].
Mitigation
Update to version 29.0.0 or later, which contains the fix. If an immediate update is not possible, consider applying a virtual patch or mitigation rule from Patchstack. Ensure that all instances of the plugin are updated promptly to prevent exploitation [1].
AI Insight generated on Jun 15, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=28.1.7
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
0No linked articles in our index yet.