HomeWordPress vulnerabilitiesContest Gallery
Contest Gallery vulnerabilities
Contest Gallery has 39 known vulnerabilities in this database. The most recent published record is dated 16 Sep 2026.
- Known vulnerabilities
- 39
- Active installs
- 1,000+
- Latest version
- 33.0.3
- Last updated
- 16 Sep 2026
- Most recent
- 16 Sep 2026
Find it in your WordPress dashboard under Plugins. Severity is based on the CVSS score published with the CVE where one is available.
| Vulnerability | Severity | Affected | Fix | Published |
|---|---|---|---|---|
| Remote code execution CVE-2026-78088 | High 8.8 | Up to 32.0.1 | Fixed in a later version (latest 33.0.3) | 16 Sep 2026 |
| SQL injection CVE-2026-16586 | Medium 6.5 | Up to 30.0.7 | Fixed in a later version (latest 33.0.3) | 15 Aug 2026 |
| Authentication bypass CVE-2026-16055 | High 7.5 | Before 30.0.7 | Fixed in 30.0.7 | 5 Aug 2026 |
| Broken access control CVE-2026-16056 | Medium 4.3 | Before 30.0.7 | Fixed in 30.0.7 | 4 Aug 2026 |
| Broken access control CVE-2026-16057 | Medium 6.5 | Before 30.0.7 | Fixed in 30.0.7 | 3 Aug 2026 |
| Privilege escalation CVE-2026-12165 | High 8.8 | Up to 30.0.2 | Fixed in a later version (latest 33.0.3) | 17 Jun 2026 |
| SQL injection CVE-2026-8912 | High 7.5 | Up to 28.1.6 | Fixed in a later version (latest 33.0.3) | 19 May 2026 |
| Authentication bypass CVE-2026-4021 | High 8.1 | Up to 28.1.5 | Fixed in a later version (latest 33.0.3) | 24 Mar 2026 |
| SQL injection CVE-2026-3180 | High 7.5 | Up to 28.1.4 | Fixed in a later version (latest 33.0.3) | 2 Mar 2026 |
| Broken access control CVE-2025-12849 | Medium 5.3 | Up to 28.0.2 | Fixed in a later version (latest 33.0.3) | 15 Nov 2025 |
| CSV injection CVE-2025-11254 | Medium 4.3 | Up to 27.0.3 | Fixed in a later version (latest 33.0.3) | 11 Oct 2025 |
| Cross-site scripting (XSS) CVE-2025-10383 | Medium 6.4 | Up to 27.0.2 | Fixed in a later version (latest 33.0.3) | 4 Oct 2025 |
| Cross-site scripting (XSS) CVE-2025-3862 | Medium 6.4 | Before 26.0.7 | Fixed in 26.0.7 | 8 May 2025 |
| Cross-site scripting (XSS) CVE-2025-1513 | High 7.2 | Before 26.0.1 | Fixed in 26.0.1 | 28 Feb 2025 |
| Privilege escalation CVE-2024-11103 | Critical 9.8 | Before 24.0.8 | Fixed in 24.0.8 | 28 Nov 2024 |
| SQL injection CVE-2024-10687 | Critical 9.8 | Before 24.0.4 | Fixed in 24.0.4 | 5 Nov 2024 |
| Cross-site scripting (XSS) CVE-2024-1487 | Medium 5.4 | Before 21.3.1 | Fixed in 21.3.1 | 11 Mar 2024 |
| Cross-site request forgery (CSRF) CVE-2024-24887 | Medium 5.4 | Before 21.2.9 | Fixed in 21.2.9 | 12 Feb 2024 |
| Cross-site scripting (XSS) CVE-2023-5307 | Medium 6.1 | Before 21.2.8.1 | Fixed in 21.2.8.1 | 31 Oct 2023 |
| Security weakness CVE-2022-4157 | Medium 4.9 | Before 19.1.5.1 | Fixed in 19.1.5.1 | 26 Dec 2022 |
| Security weakness CVE-2022-4158 | High 7.5 | Before 19.1.5.1 | Fixed in 19.1.5.1 | 26 Dec 2022 |
| Security weakness CVE-2022-4159 | Medium 6.5 | Before 19.1.5.1 | Fixed in 19.1.5.1 | 26 Dec 2022 |
| Security weakness CVE-2022-4160 | Medium 6.5 | Before 19.1.5.1 | Fixed in 19.1.5.1 | 26 Dec 2022 |
| SQL injection CVE-2022-4161 | Medium 6.5 | Before 19.1.5.1 | Fixed in 19.1.5.1 | 26 Dec 2022 |
| Security weakness CVE-2022-4162 | Medium 6.5 | Before 19.1.5.1 | Fixed in 19.1.5.1 | 26 Dec 2022 |
| Security weakness CVE-2022-4163 | Medium 6.5 | Before 19.1.5.1 | Fixed in 19.1.5.1 | 26 Dec 2022 |
| Security weakness CVE-2022-4164 | Medium 6.5 | Before 19.1.5.1 | Fixed in 19.1.5.1 | 26 Dec 2022 |
| Security weakness CVE-2022-4165 | Medium 6.5 | Before 19.1.5.1 | Fixed in 19.1.5.1 | 26 Dec 2022 |
| Security weakness CVE-2022-4166 | Medium 6.5 | Before 19.1.5.1 | Fixed in 19.1.5.1 | 26 Dec 2022 |
| Security weakness CVE-2022-4150 | Medium 6.5 | Before 19.1.5.1 | Fixed in 19.1.5.1 | 26 Dec 2022 |
| SQL injection CVE-2022-4151 | Medium 6.5 | Before 19.1.5.1 | Fixed in 19.1.5.1 | 26 Dec 2022 |
| Security weakness CVE-2022-4152 | Medium 6.5 | Before 19.1.5.1 | Fixed in 19.1.5.1 | 26 Dec 2022 |
| Security weakness CVE-2022-4153 | Medium 6.5 | Before 19.1.5.1 | Fixed in 19.1.5.1 | 26 Dec 2022 |
| Security weakness CVE-2022-4154 | Medium 4.9 | Before 19.1.5.1 | Fixed in 19.1.5.1 | 26 Dec 2022 |
| Security weakness CVE-2022-4155 | Medium 4.9 | Before 19.1.5.1 | Fixed in 19.1.5.1 | 26 Dec 2022 |
| Security weakness CVE-2022-4156 | High 7.5 | Before 19.1.5.1 | Fixed in 19.1.5.1 | 26 Dec 2022 |
| Cross-site scripting (XSS) CVE-2022-45848 | Medium 6.1 | Up to 13.1.0.9 | Fixed in a later version (latest 33.0.3) | 6 Dec 2022 |
| SQL injection CVE-2022-36394 | High 7.6 | Up to 17.0.4 | Fixed in a later version (latest 33.0.3) | 23 Aug 2022 |
| SQL injection CVE-2021-24915 | Critical 9.8 | Before 13.1.0.6 | Fixed in 13.1.0.6 | 29 Nov 2021 |
Read the published descriptions
- CVE-2026-78088, 16 Sep 2026
- The Contest Gallery - Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path validation in the 'baseUrlForFacebook' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite known files which may lead to remote code execution when certain preconditions are met. CVE record
- CVE-2026-16586, 15 Aug 2026
- The Contest Gallery - Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Second-Order SQL Injection via MultipleFiles Second-Order Payload via 'cg_multiple_files_for_post' -> 'cgRealId' in all versions up to, and including, 30.0.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2026-16055, 5 Aug 2026
- The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery WordPress plugin before 30.0.7 and enables unlimited, unthrottled password guessing against any account (including administrators) up to full account takeover. CVE record
- CVE-2026-16056, 4 Aug 2026
- The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history. CVE record
- CVE-2026-16057, 3 Aug 2026
- The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts, pages, and other content they do not own. CVE record
- CVE-2026-12165, 17 Jun 2026
- The Contest Gallery - Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 30.0.2 via the `RegistryUserRole` parameter. This is due to the plugin's admin menu being registered at the `edit_posts` capability level - granting Contributor-level users access to the plugin's admin pages and a valid `cg_admin` nonce - while the option-saving handler in `change-options-and-sizes.php` performs no `current_user_can()` capability check beyond `check_admin_referer('cg_admin')`, and the `RegistryUserRole` value is processed only through `sanitize_text_field()` and `htmlentities()` without restriction to an allowlist of permitted role names. This makes it possible for authenticated attackers, with author-level access and above, to overwrite the plugin's stored `RegistryUserRole` option with `administrator`, which the `cg_create_wp_user_from_google_user` function then reads back from the `contest_gal1ery_registry_and_login_options` database table without any allowlist validation and passes directly to `wp_update_user()`, effectively promoting a newly registered Google sign-in account to Administrator. CVE record
- CVE-2026-8912, 19 May 2026
- The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to, and including, 28.1.6. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query inside the unauthenticated 'post_cg_gallery_form_upload' AJAX action (specifically the 'cb' branch of the included users-upload-check.php, where $f_input_id is concatenated unquoted into 'SELECT Field_Content FROM ... WHERE id = $f_input_id'). The endpoint is gated only by a public frontend nonce ('cg1l_action' / 'cg_nonce') that is exposed in the page source of any public gallery page. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2026-4021, 24 Mar 2026
- The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in all versions up to, and including, 28.1.5. This is due to the email confirmation handler in `users-registry-check-after-email-or-pin-confirmation.php` using the user's email string in a `WHERE ID = %s` clause instead of the numeric user ID, combined with an unauthenticated key-based login endpoint in `ajax-functions-frontend.php`. When the non-default `RegMailOptional=1` setting is enabled, an attacker can register with a crafted email starting with the target user ID (e.g., `1poc@example.test`), trigger the confirmation flow to overwrite the admin's `user_activation_key` via MySQL integer coercion, and then use the `post_cg1l_login_user_by_key` AJAX action to authenticate as the admin without any credentials. This makes it possible for unauthenticated attackers to take over any WordPress administrator account and gain full site control. CVE record
- CVE-2026-3180, 2 Mar 2026
- The Contest Gallery - Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to blind SQL Injection via the ‘cgLostPasswordEmail’ and the ’cgl_mail’ parameter in all versions up to, and including, 28.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerability's ’cgLostPasswordEmail’ parameter was patched in version 28.1.4, and the ’cgl_mail’ parameter was patched in version 28.1.5. CVE record
- CVE-2025-12849, 15 Nov 2025
- The Contest Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 28.0.2. This is due to the plugin registering the `cg_check_wp_admin_upload_v10` AJAX action for both authenticated and unauthenticated users without implementing capability checks or nonce verification. This makes it possible for unauthenticated attackers to inject arbitrary WordPress media attachments into galleries and manipulate gallery metadata via the `cg_check_wp_admin_upload_v10` action. It does not enable an attacker to move or upload files. CVE record
- CVE-2025-11254, 11 Oct 2025
- The Contest Gallery - Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 27.0.3 via gallery submissions. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration. CVE record
- CVE-2025-10383, 4 Oct 2025
- The Contest Gallery - Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple form field parameters in all versions up to, and including, 27.0.2. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with author-level access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2025-3862, 8 May 2025
- Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 26.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2025-1513, 28 Feb 2025
- The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery - Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Name and Comment field when commenting on photo gallery entries in all versions up to, and including, 26.0.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE record
- CVE-2024-11103, 28 Nov 2024
- The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account. CVE record
- CVE-2024-10687, 5 Nov 2024
- The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery - Upload, Vote, Sell via PayPal, Social Share Buttons plugin for WordPress is vulnerable to time-based SQL Injection via the $collectedIds parameter in all versions up to, and including, 24.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. CVE record
- CVE-2024-1487, 11 Mar 2024
- The Photos and Files Contest Gallery WordPress plugin before 21.3.1 does not sanitize and escape some parameters, which could allow users with a role as low as author to perform Cross-Site Scripting attacks. CVE record
- CVE-2024-24887, 12 Feb 2024
- Cross-Site Request Forgery (CSRF) vulnerability in Contest Gallery Photos and Files Contest Gallery - Contact Form, Upload Form, Social Share and Voting Plugin for WordPress.This issue affects Photos and Files Contest Gallery - Contact Form, Upload Form, Social Share and Voting Plugin for WordPress: from n/a through 21.2.8.4. CVE record
- CVE-2023-5307, 31 Oct 2023
- The Photos and Files Contest Gallery WordPress plugin before 21.2.8.1 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks via certain headers. CVE record
- CVE-2022-4157, 26 Dec 2022
- The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_option_id POST parameter before concatenating it to an SQL query in export-votes-all.php. This may allow malicious users with administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the site's database. CVE record
- CVE-2022-4158, 26 Dec 2022
- The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_Fields POST parameter before concatenating it to an SQL query in users-registry-check-registering-and-login.php. This may allow malicious visitors to leak sensitive information from the site's database. CVE record
- CVE-2022-4159, 26 Dec 2022
- The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_id POST parameter before concatenating it to an SQL query in 0_change-gallery.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
- CVE-2022-4160, 26 Dec 2022
- The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_copy_id POST parameter before concatenating it to an SQL query in cg-copy-comments.php and cg-copy-rating.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
- CVE-2022-4161, 26 Dec 2022
- The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_copy_start POST parameter before concatenating it to an SQL query in copy-gallery-images.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
- CVE-2022-4162, 26 Dec 2022
- The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_row POST parameter before concatenating it to an SQL query in 3_row-order.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
- CVE-2022-4163, 26 Dec 2022
- The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_deactivate and cg_activate POST parameters before concatenating it to an SQL query in 2_deactivate.php and 4_activate.php, respectively. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
- CVE-2022-4164, 26 Dec 2022
- The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_multiple_files_for_post POST parameter before concatenating it to an SQL query in 0_change-gallery.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
- CVE-2022-4165, 26 Dec 2022
- The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_order POST parameter before concatenating it to an SQL query in order-custom-fields-with-and-without-search.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
- CVE-2022-4166, 26 Dec 2022
- The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the addCountS POST parameter before concatenating it to an SQL query in 4_activate.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
- CVE-2022-4150, 26 Dec 2022
- The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id POST parameter before concatenating it to an SQL query in order-custom-fields-with-and-without-search.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
- CVE-2022-4151, 26 Dec 2022
- The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id GET parameter before concatenating it to an SQL query in export-images-data.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
- CVE-2022-4152, 26 Dec 2022
- The Contest Gallery WordPress plugin before 19.1.5, Contest Gallery Pro WordPress plugin before 19.1.5 do not escape the option_id POST parameter before concatenating it to an SQL query in edit-options.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
- CVE-2022-4153, 26 Dec 2022
- The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the upload[] POST parameter before concatenating it to an SQL query in get-data-create-upload-v10.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
- CVE-2022-4154, 26 Dec 2022
- The Contest Gallery Pro WordPress plugin before 19.1.5 does not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with at administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the site's database. CVE record
- CVE-2022-4155, 26 Dec 2022
- The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the site's database. CVE record
- CVE-2022-4156, 26 Dec 2022
- The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the user_id POST parameter before concatenating it to an SQL query in ajax-functions-backend.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. CVE record
- CVE-2022-45848, 6 Dec 2022
- Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 13.1.0.9 on WordPress. CVE record
- CVE-2022-36394, 23 Aug 2022
- Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at WordPress. CVE record
- CVE-2021-24915, 29 Nov 2021
- The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address CVE record
What to do if you run Contest Gallery
If you run Contest Gallery, open WordPress and check the installed version in Plugins. Compare it with the affected versions in the vulnerability record. If a fixed version is available, take a current backup and update to that version or the latest supported release.
If no fixed version exists, consider disabling and removing the plugin or replacing it with a maintained alternative. After dealing with the affected software, check administrator users, unexpected file changes, redirects, unfamiliar pages and security logs for signs that the site may already have been altered.
Email me about new Contest Gallery vulnerabilities
Free. We email you when a new vulnerability is published for Contest Gallery, usually within minutes. Confirm by email; unsubscribe any time.
Focus on your business. We’ll take care of your website.
From everyday updates to ongoing care, we keep your website working.