Website support, maintenance and fixes for UK businessesCall 0208 088 8371info@websupportservices.co.uk

HomeWordPress vulnerabilitiesContest Gallery

Contest Gallery vulnerabilities

Contest Gallery has 39 known vulnerabilities in this database. The most recent published record is dated 16 Sep 2026.

Known vulnerabilities
39
Active installs
1,000+
Latest version
33.0.3
Last updated
16 Sep 2026
Most recent
16 Sep 2026

Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.

VulnerabilitySeverityAffectedFixPublished
Remote code execution
CVE-2026-78088
High 8.8Up to 32.0.1Fixed in a later version (latest 33.0.3)16 Sep 2026
SQL injection
CVE-2026-16586
Medium 6.5Up to 30.0.7Fixed in a later version (latest 33.0.3)15 Aug 2026
Authentication bypass
CVE-2026-16055
High 7.5Before 30.0.7Fixed in 30.0.75 Aug 2026
Broken access control
CVE-2026-16056
Medium 4.3Before 30.0.7Fixed in 30.0.74 Aug 2026
Broken access control
CVE-2026-16057
Medium 6.5Before 30.0.7Fixed in 30.0.73 Aug 2026
Privilege escalation
CVE-2026-12165
High 8.8Up to 30.0.2Fixed in a later version (latest 33.0.3)17 Jun 2026
SQL injection
CVE-2026-8912
High 7.5Up to 28.1.6Fixed in a later version (latest 33.0.3)19 May 2026
Authentication bypass
CVE-2026-4021
High 8.1Up to 28.1.5Fixed in a later version (latest 33.0.3)24 Mar 2026
SQL injection
CVE-2026-3180
High 7.5Up to 28.1.4Fixed in a later version (latest 33.0.3)2 Mar 2026
Broken access control
CVE-2025-12849
Medium 5.3Up to 28.0.2Fixed in a later version (latest 33.0.3)15 Nov 2025
CSV injection
CVE-2025-11254
Medium 4.3Up to 27.0.3Fixed in a later version (latest 33.0.3)11 Oct 2025
Cross-site scripting (XSS)
CVE-2025-10383
Medium 6.4Up to 27.0.2Fixed in a later version (latest 33.0.3)4 Oct 2025
Cross-site scripting (XSS)
CVE-2025-3862
Medium 6.4Before 26.0.7Fixed in 26.0.78 May 2025
Cross-site scripting (XSS)
CVE-2025-1513
High 7.2Before 26.0.1Fixed in 26.0.128 Feb 2025
Privilege escalation
CVE-2024-11103
Critical 9.8Before 24.0.8Fixed in 24.0.828 Nov 2024
SQL injection
CVE-2024-10687
Critical 9.8Before 24.0.4Fixed in 24.0.45 Nov 2024
Cross-site scripting (XSS)
CVE-2024-1487
Medium 5.4Before 21.3.1Fixed in 21.3.111 Mar 2024
Cross-site request forgery (CSRF)
CVE-2024-24887
Medium 5.4Before 21.2.9Fixed in 21.2.912 Feb 2024
Cross-site scripting (XSS)
CVE-2023-5307
Medium 6.1Before 21.2.8.1Fixed in 21.2.8.131 Oct 2023
Security weakness
CVE-2022-4157
Medium 4.9Before 19.1.5.1Fixed in 19.1.5.126 Dec 2022
Security weakness
CVE-2022-4158
High 7.5Before 19.1.5.1Fixed in 19.1.5.126 Dec 2022
Security weakness
CVE-2022-4159
Medium 6.5Before 19.1.5.1Fixed in 19.1.5.126 Dec 2022
Security weakness
CVE-2022-4160
Medium 6.5Before 19.1.5.1Fixed in 19.1.5.126 Dec 2022
SQL injection
CVE-2022-4161
Medium 6.5Before 19.1.5.1Fixed in 19.1.5.126 Dec 2022
Security weakness
CVE-2022-4162
Medium 6.5Before 19.1.5.1Fixed in 19.1.5.126 Dec 2022
Security weakness
CVE-2022-4163
Medium 6.5Before 19.1.5.1Fixed in 19.1.5.126 Dec 2022
Security weakness
CVE-2022-4164
Medium 6.5Before 19.1.5.1Fixed in 19.1.5.126 Dec 2022
Security weakness
CVE-2022-4165
Medium 6.5Before 19.1.5.1Fixed in 19.1.5.126 Dec 2022
Security weakness
CVE-2022-4166
Medium 6.5Before 19.1.5.1Fixed in 19.1.5.126 Dec 2022
Security weakness
CVE-2022-4150
Medium 6.5Before 19.1.5.1Fixed in 19.1.5.126 Dec 2022
SQL injection
CVE-2022-4151
Medium 6.5Before 19.1.5.1Fixed in 19.1.5.126 Dec 2022
Security weakness
CVE-2022-4152
Medium 6.5Before 19.1.5.1Fixed in 19.1.5.126 Dec 2022
Security weakness
CVE-2022-4153
Medium 6.5Before 19.1.5.1Fixed in 19.1.5.126 Dec 2022
Security weakness
CVE-2022-4154
Medium 4.9Before 19.1.5.1Fixed in 19.1.5.126 Dec 2022
Security weakness
CVE-2022-4155
Medium 4.9Before 19.1.5.1Fixed in 19.1.5.126 Dec 2022
Security weakness
CVE-2022-4156
High 7.5Before 19.1.5.1Fixed in 19.1.5.126 Dec 2022
Cross-site scripting (XSS)
CVE-2022-45848
Medium 6.1Up to 13.1.0.9Fixed in a later version (latest 33.0.3)6 Dec 2022
SQL injection
CVE-2022-36394
High 7.6Up to 17.0.4Fixed in a later version (latest 33.0.3)23 Aug 2022
SQL injection
CVE-2021-24915
Critical 9.8Before 13.1.0.6Fixed in 13.1.0.629 Nov 2021
Read the published descriptions
CVE-2026-78088, 16 Sep 2026
The Contest Gallery - Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path validation in the 'baseUrlForFacebook' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite known files which may lead to remote code execution when certain preconditions are met. CVE record
CVE-2026-16586, 15 Aug 2026
The Contest Gallery - Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Second-Order SQL Injection via MultipleFiles Second-Order Payload via 'cg_multiple_files_for_post' -> 'cgRealId' in all versions up to, and including, 30.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2026-16055, 5 Aug 2026
The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery WordPress plugin before 30.0.7 and enables unlimited, unthrottled password guessing against any account (including administrators) up to full account takeover. CVE record
CVE-2026-16056, 4 Aug 2026
The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history. CVE record
CVE-2026-16057, 3 Aug 2026
The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts, pages, and other content they do not own. CVE record
CVE-2026-12165, 17 Jun 2026
The Contest Gallery - Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 30.0.2 via the `RegistryUserRole` parameter. This is due to the plugin's admin menu being registered at the `edit_posts` capability level - granting Contributor-level users access to the plugin's admin pages and a valid `cg_admin` nonce - while the option-saving handler in `change-options-and-sizes.php` performs no `current_user_can()` capability check beyond `check_admin_referer('cg_admin')`, and the `RegistryUserRole` value is processed only through `sanitize_text_field()` and `htmlentities()` without restriction to an allowlist of permitted role names. This makes it possible for authenticated attackers, with author-level access and above, to overwrite the plugin's stored `RegistryUserRole` option with `administrator`, which the `cg_create_wp_user_from_google_user` function then reads back from the `contest_gal1ery_registry_and_login_options` database table without any allowlist validation and passes directly to `wp_update_user()`, effectively promoting a newly registered Google sign-in account to Administrator. CVE record
CVE-2026-8912, 19 May 2026
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to, and including, 28.1.6. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query inside the unauthenticated 'post_cg_gallery_form_upload' AJAX action (specifically the 'cb' branch of the included users-upload-check.php, where $f_input_id is concatenated unquoted into 'SELECT Field_Content FROM ... WHERE id = $f_input_id'). The endpoint is gated only by a public frontend nonce ('cg1l_action' / 'cg_nonce') that is exposed in the page source of any public gallery page. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2026-4021, 24 Mar 2026
The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in all versions up to, and including, 28.1.5. This is due to the email confirmation handler in `users-registry-check-after-email-or-pin-confirmation.php` using the user's email string in a `WHERE ID = %s` clause instead of the numeric user ID, combined with an unauthenticated key-based login endpoint in `ajax-functions-frontend.php`. When the non-default `RegMailOptional=1` setting is enabled, an attacker can register with a crafted email starting with the target user ID (e.g., `1poc@example.test`), trigger the confirmation flow to overwrite the admin's `user_activation_key` via MySQL integer coercion, and then use the `post_cg1l_login_user_by_key` AJAX action to authenticate as the admin without any credentials. This makes it possible for unauthenticated attackers to take over any WordPress administrator account and gain full site control. CVE record
CVE-2026-3180, 2 Mar 2026
The Contest Gallery - Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to blind SQL Injection via the ‘cgLostPasswordEmail’ and the ’cgl_mail’ parameter in all versions up to, and including, 28.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerability's ’cgLostPasswordEmail’ parameter was patched in version 28.1.4, and the ’cgl_mail’ parameter was patched in version 28.1.5. CVE record
CVE-2025-12849, 15 Nov 2025
The Contest Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 28.0.2. This is due to the plugin registering the `cg_check_wp_admin_upload_v10` AJAX action for both authenticated and unauthenticated users without implementing capability checks or nonce verification. This makes it possible for unauthenticated attackers to inject arbitrary WordPress media attachments into galleries and manipulate gallery metadata via the `cg_check_wp_admin_upload_v10` action. It does not enable an attacker to move or upload files. CVE record
CVE-2025-11254, 11 Oct 2025
The Contest Gallery - Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 27.0.3 via gallery submissions. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration. CVE record
CVE-2025-10383, 4 Oct 2025
The Contest Gallery - Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple form field parameters in all versions up to, and including, 27.0.2. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with author-level access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-3862, 8 May 2025
Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 26.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2025-1513, 28 Feb 2025
The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery - Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Name and Comment field when commenting on photo gallery entries in all versions up to, and including, 26.0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
CVE-2024-11103, 28 Nov 2024
The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account. CVE record
CVE-2024-10687, 5 Nov 2024
The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery - Upload, Vote, Sell via PayPal, Social Share Buttons plugin for WordPress is vulnerable to time-based SQL Injection via the $collectedIds parameter in all versions up to, and including, 24.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
CVE-2024-1487, 11 Mar 2024
The Photos and Files Contest Gallery WordPress plugin before 21.3.1 does not sanitize and escape some parameters, which could allow users with a role as low as author to perform Cross-Site Scripting attacks. CVE record
CVE-2024-24887, 12 Feb 2024
Cross-Site Request Forgery (CSRF) vulnerability in Contest Gallery Photos and Files Contest Gallery - Contact Form, Upload Form, Social Share and Voting Plugin for WordPress.This issue affects Photos and Files Contest Gallery - Contact Form, Upload Form, Social Share and Voting Plugin for WordPress: from n/a through 21.2.8.4. CVE record
CVE-2023-5307, 31 Oct 2023
The Photos and Files Contest Gallery WordPress plugin before 21.2.8.1 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks via certain headers. CVE record
CVE-2022-4157, 26 Dec 2022
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_option_id POST parameter before concatenating it to an SQL query in export-votes-all.php. This may allow malicious users with administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the site's database. CVE record
CVE-2022-4158, 26 Dec 2022
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_Fields POST parameter before concatenating it to an SQL query in users-registry-check-registering-and-login.php. This may allow malicious visitors to leak sensitive information from the site's database. CVE record
CVE-2022-4159, 26 Dec 2022
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_id POST parameter before concatenating it to an SQL query in 0_change-gallery.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
CVE-2022-4160, 26 Dec 2022
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_copy_id POST parameter before concatenating it to an SQL query in cg-copy-comments.php and cg-copy-rating.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
CVE-2022-4161, 26 Dec 2022
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_copy_start POST parameter before concatenating it to an SQL query in copy-gallery-images.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
CVE-2022-4162, 26 Dec 2022
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_row POST parameter before concatenating it to an SQL query in 3_row-order.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
CVE-2022-4163, 26 Dec 2022
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_deactivate and cg_activate POST parameters before concatenating it to an SQL query in 2_deactivate.php and 4_activate.php, respectively. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
CVE-2022-4164, 26 Dec 2022
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_multiple_files_for_post POST parameter before concatenating it to an SQL query in 0_change-gallery.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
CVE-2022-4165, 26 Dec 2022
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_order POST parameter before concatenating it to an SQL query in order-custom-fields-with-and-without-search.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
CVE-2022-4166, 26 Dec 2022
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the addCountS POST parameter before concatenating it to an SQL query in 4_activate.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
CVE-2022-4150, 26 Dec 2022
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id POST parameter before concatenating it to an SQL query in order-custom-fields-with-and-without-search.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
CVE-2022-4151, 26 Dec 2022
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id GET parameter before concatenating it to an SQL query in export-images-data.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
CVE-2022-4152, 26 Dec 2022
The Contest Gallery WordPress plugin before 19.1.5, Contest Gallery Pro WordPress plugin before 19.1.5 do not escape the option_id POST parameter before concatenating it to an SQL query in edit-options.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
CVE-2022-4153, 26 Dec 2022
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the upload[] POST parameter before concatenating it to an SQL query in get-data-create-upload-v10.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
CVE-2022-4154, 26 Dec 2022
The Contest Gallery Pro WordPress plugin before 19.1.5 does not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with at administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the site's database. CVE record
CVE-2022-4155, 26 Dec 2022
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the site's database. CVE record
CVE-2022-4156, 26 Dec 2022
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the user_id POST parameter before concatenating it to an SQL query in ajax-functions-backend.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
CVE-2022-45848, 6 Dec 2022
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 13.1.0.9 on WordPress. CVE record
CVE-2022-36394, 23 Aug 2022
Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at WordPress. CVE record
CVE-2021-24915, 29 Nov 2021
The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address CVE record

What to do if you run Contest Gallery

If you run Contest Gallery, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.

If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.

Email me about new Contest Gallery vulnerabilities

Free. We email you when a new vulnerability is published for Contest Gallery, usually within minutes. Confirm by email; unsubscribe any time.

Focus on your business. We’ll take care of your website.

From everyday updates to ongoing care, we keep your website working.

Get website support