Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-62950-PoC — Proof-of-concept exploit for a Cross-Site Request Forgery (CSRF) vulnerability in Contest Gallery WordPress plugin, enabling unauthorized gallery item deletion. | Kitploit
Tools/GitHubGitHub/lorenzocamilli/cve-2025-62950-poc
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHublorenzocamilli/cve-2025-62950-poc

CVE-2025-62950-PoC

Proof-of-concept exploit for a Cross-Site Request Forgery (CSRF) vulnerability in Contest Gallery WordPress plugin, enabling unauthorized gallery item deletion.

View Repository
29 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Description

This proof of concept (PoC) describes a Cross-Site Request Forgery (CSRF) vulnerability found in the Contest Gallery – Upload, Vote & Sell with PayPal and Stripe v. 26.1.2 plugin. The issue allows an attacker to trick an authenticated user into executing a crafted request that unintentionally deletes a gallery item without their consent, leading to unauthorized content loss and affecting data integrity.

Details

  • Vulnerability Type: Cross-Site Request Forgery (CSRF)
  • Affected Plugin: Contest Gallery – Upload, Vote & Sell with PayPal and Stripe v. 26.1.2

Impact

An attacker could trigger unintended operations, specifically the deletion of gallery items—without the user’s awareness or explicit permission. Successful exploitation may lead to unauthorized content removal and poses a risk to data integrity within the system.

References

  • WPScan
Download Tool