
Proof-of-concept exploit for a Cross-Site Request Forgery (CSRF) vulnerability in Contest Gallery WordPress plugin, enabling unauthorized gallery item deletion.
This proof of concept (PoC) describes a Cross-Site Request Forgery (CSRF) vulnerability found in the Contest Gallery – Upload, Vote & Sell with PayPal and Stripe v. 26.1.2 plugin. The issue allows an attacker to trick an authenticated user into executing a crafted request that unintentionally deletes a gallery item without their consent, leading to unauthorized content loss and affecting data integrity.
An attacker could trigger unintended operations, specifically the deletion of gallery items—without the user’s awareness or explicit permission. Successful exploitation may lead to unauthorized content removal and poses a risk to data integrity within the system.