Contest Gallery Pro <= 29.0.1 - Unauthenticated Privilege Escalation
critical
The Contest Gallery Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 29.0.1. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
- CVSS:
- 9.8
- Affected:
- up to 29.0.1
- Fixed in:
- 29.0.2
- Disclosed:
- May 17, 2026
CVE-2026-42680 on NVD →
Contest Gallery Pro [contest-gallery-pro] < 19.1.5.1
unknown
[en] The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_order POST parameter before concatenating it to an SQL query in order-custom-fields-with-and-without-search.php. This may allow malicious users with at least author privilege to leak sens...
- Affected:
- up to 19.1.5.1
- Fixed in:
- 19.1.5.1
- Disclosed:
- Dec 26, 2022
CVE-2022-4165 on NVD →
Contest Gallery Pro [contest-gallery-pro] < 19.1.5.1
unknown
[en] The Contest Gallery Pro WordPress plugin before 19.1.5 does not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with at administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from th...
- Affected:
- up to 19.1.5.1
- Fixed in:
- 19.1.5.1
- Disclosed:
- Dec 26, 2022
CVE-2022-4154 on NVD →
Contest Gallery Pro [contest-gallery-pro] < 19.1.5.1
unknown
[en] The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_row POST parameter before concatenating it to an SQL query in 3_row-order.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's...
- Affected:
- up to 19.1.5.1
- Fixed in:
- 19.1.5.1
- Disclosed:
- Dec 26, 2022
CVE-2022-4162 on NVD →
Contest Gallery Pro [contest-gallery-pro] < 19.1.5.1
unknown
[en] The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_id POST parameter before concatenating it to an SQL query in 0_change-gallery.php. This may allow malicious users with at least author privilege to leak sensitive information from the sit...
- Affected:
- up to 19.1.5.1
- Fixed in:
- 19.1.5.1
- Disclosed:
- Dec 26, 2022
CVE-2022-4159 on NVD →
Contest Gallery Pro [contest-gallery-pro] < 19.1.5.1
unknown
[en] The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the upload[] POST parameter before concatenating it to an SQL query in get-data-create-upload-v10.php. This may allow malicious users with at least author privilege to leak sensitive information...
- Affected:
- up to 19.1.5.1
- Fixed in:
- 19.1.5.1
- Disclosed:
- Dec 26, 2022
CVE-2022-4153 on NVD →
Contest Gallery Pro [contest-gallery-pro] < 19.1.5.1
unknown
[en] The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the addCountS POST parameter before concatenating it to an SQL query in 4_activate.php. This may allow malicious users with at least author privilege to leak sensitive information from the site'...
- Affected:
- up to 19.1.5.1
- Fixed in:
- 19.1.5.1
- Disclosed:
- Dec 26, 2022
CVE-2022-4166 on NVD →
Contest Gallery Pro [contest-gallery-pro] < 19.1.5.1
unknown
[en] The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id GET parameter before concatenating it to an SQL query in export-images-data.php. This may allow malicious users with at least author privilege to leak sensitive information from th...
- Affected:
- up to 19.1.5.1
- Fixed in:
- 19.1.5.1
- Disclosed:
- Dec 26, 2022
CVE-2022-4151 on NVD →
Contest Gallery Pro [contest-gallery-pro] < 19.1.5.1
unknown
[en] The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_deactivate and cg_activate POST parameters before concatenating it to an SQL query in 2_deactivate.php and 4_activate.php, respectively. This may allow malicious users with at least auth...
- Affected:
- up to 19.1.5.1
- Fixed in:
- 19.1.5.1
- Disclosed:
- Dec 26, 2022
CVE-2022-4163 on NVD →
Contest Gallery Pro [contest-gallery-pro] < 19.1.5.1
unknown
[en] The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the option_id POST parameter before concatenating it to an SQL query in order-custom-fields-with-and-without-search.php. This may allow malicious users with at least author privilege to leak sen...
- Affected:
- up to 19.1.5.1
- Fixed in:
- 19.1.5.1
- Disclosed:
- Dec 26, 2022
CVE-2022-4150 on NVD →
Contest Gallery Pro [contest-gallery-pro] < 19.1.5.1
unknown
[en] The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the user_id POST parameter before concatenating it to an SQL query in ajax-functions-backend.php. This may allow malicious users with at least author privilege to leak sensitive information from...
- Affected:
- up to 19.1.5.1
- Fixed in:
- 19.1.5.1
- Disclosed:
- Dec 26, 2022
CVE-2022-4156 on NVD →
Contest Gallery Pro [contest-gallery-pro] < 19.1.5.1
unknown
[en] The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with administrator privileges (i.e. on multisite WordPress config...
- Affected:
- up to 19.1.5.1
- Fixed in:
- 19.1.5.1
- Disclosed:
- Dec 26, 2022
CVE-2022-4155 on NVD →
Contest Gallery Pro [contest-gallery-pro] < 19.1.5.1
unknown
[en] The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_option_id POST parameter before concatenating it to an SQL query in export-votes-all.php. This may allow malicious users with administrator privileges (i.e. on multisite WordPress configu...
- Affected:
- up to 19.1.5.1
- Fixed in:
- 19.1.5.1
- Disclosed:
- Dec 26, 2022
CVE-2022-4157 on NVD →
Contest Gallery Pro [contest-gallery-pro] < 19.1.5.1
unknown
[en] The Contest Gallery WordPress plugin before 19.1.5, Contest Gallery Pro WordPress plugin before 19.1.5 do not escape the option_id POST parameter before concatenating it to an SQL query in edit-options.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's...
- Affected:
- up to 19.1.5.1
- Fixed in:
- 19.1.5.1
- Disclosed:
- Dec 26, 2022
CVE-2022-4152 on NVD →
Contest Gallery Pro [contest-gallery-pro] < 19.1.5.1
unknown
[en] The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_multiple_files_for_post POST parameter before concatenating it to an SQL query in 0_change-gallery.php. This may allow malicious users with at least author privilege to leak sensitive inf...
- Affected:
- up to 19.1.5.1
- Fixed in:
- 19.1.5.1
- Disclosed:
- Dec 26, 2022
CVE-2022-4164 on NVD →
Contest Gallery Pro [contest-gallery-pro] < 19.1.5.1
unknown
[en] The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_copy_start POST parameter before concatenating it to an SQL query in copy-gallery-images.php. This may allow malicious users with at least author privilege to leak sensitive information f...
- Affected:
- up to 19.1.5.1
- Fixed in:
- 19.1.5.1
- Disclosed:
- Dec 26, 2022
CVE-2022-4161 on NVD →
Contest Gallery Pro [contest-gallery-pro] < 19.1.5.1
unknown
[en] The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_copy_id POST parameter before concatenating it to an SQL query in cg-copy-comments.php and cg-copy-rating.php. This may allow malicious users with at least author privilege to leak sensi...
- Affected:
- up to 19.1.5.1
- Fixed in:
- 19.1.5.1
- Disclosed:
- Dec 26, 2022
CVE-2022-4160 on NVD →
Contest Gallery Pro [contest-gallery-pro] < 19.1.5.1
unknown
[en] The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_Fields POST parameter before concatenating it to an SQL query in users-registry-check-registering-and-login.php. This may allow malicious visitors to leak sensitive information from the s...
- Affected:
- up to 19.1.5.1
- Fixed in:
- 19.1.5.1
- Disclosed:
- Dec 26, 2022
CVE-2022-4158 on NVD →
Contest Gallery (Pro) <= 19.1.5 - SQL Injection via option_id
high
The Contest Gallery (Pro) plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to insufficient escaping on the user supplied option_id parameter and lack of sufficient preparation on the existing SQL query in the order-custom-fields-with-and-without-search.php file. This make...
- CVSS:
- 8.8
- Affected:
- up to 19.1.5
- Fixed in:
- 19.1.5.1
- Disclosed:
- Dec 5, 2022
CVE-2022-4150 on NVD →
Contest Gallery <= 19.1.4.1 - Unauthenticated SQL Injection via cg_Fields
high
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_Fields parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional...
- CVSS:
- 8.1
- Affected:
- up to 19.1.4.1
- Fixed in:
- 19.1.5
- Disclosed:
- Dec 5, 2022
CVE-2022-4158 on NVD →
Contest Gallery <= 19.1.5 - Unauthenticated SQL Injection via user_id
high
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to insufficient escaping on the user supplied user_id parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL...
- CVSS:
- 8.1
- Affected:
- up to 19.1.5
- Fixed in:
- 19.1.5.1
- Disclosed:
- Dec 5, 2022
CVE-2022-4156 on NVD →
Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via addCountS
high
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied addCountS parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level pri...
- CVSS:
- 7.5
- Affected:
- up to 19.1.4.1
- Fixed in:
- 19.1.5
- Disclosed:
- Dec 5, 2022
CVE-2022-4166 on NVD →
Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_option_id
high
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_option_id parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level...
- CVSS:
- 7.5
- Affected:
- up to 19.1.4.1
- Fixed in:
- 19.1.5
- Disclosed:
- Dec 5, 2022
CVE-2022-4157 on NVD →
Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via wp_user_id
high
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied wp_user_id parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level pr...
- CVSS:
- 7.5
- Affected:
- up to 19.1.4.1
- Fixed in:
- 19.1.5
- Disclosed:
- Dec 5, 2022
CVE-2022-4155 on NVD →
Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_multiple_files_for_post
high
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_multiple_files_for_post parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with...
- CVSS:
- 7.5
- Affected:
- up to 19.1.4.1
- Fixed in:
- 19.1.5
- Disclosed:
- Dec 5, 2022
CVE-2022-4164 on NVD →
Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_copy_id
high
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_copy_id parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level p...
- CVSS:
- 7.5
- Affected:
- up to 19.1.4.1
- Fixed in:
- 19.1.5
- Disclosed:
- Dec 5, 2022
CVE-2022-4160 on NVD →
Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_copy_start
high
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_copy_start parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level...
- CVSS:
- 7.5
- Affected:
- up to 19.1.4.1
- Fixed in:
- 19.1.5
- Disclosed:
- Dec 5, 2022
CVE-2022-4161 on NVD →
Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via option_id GET
high
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied option_id GET parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level...
- CVSS:
- 7.5
- Affected:
- up to 19.1.4.1
- Fixed in:
- 19.1.5
- Disclosed:
- Dec 5, 2022
CVE-2022-4152 on NVD →
Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_order
high
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_order parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level priv...
- CVSS:
- 7.5
- Affected:
- up to 19.1.4.1
- Fixed in:
- 19.1.5
- Disclosed:
- Dec 5, 2022
CVE-2022-4165 on NVD →
Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_row
high
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_row parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level privil...
- CVSS:
- 7.5
- Affected:
- up to 19.1.4.1
- Fixed in:
- 19.1.5
- Disclosed:
- Dec 5, 2022
CVE-2022-4162 on NVD →
Contest Gallery <= 19.1.5 - Authenticated (Author+) SQL Injection via cg_id
high
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to insufficient escaping on the user supplied cg_id parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level privilege...
- CVSS:
- 7.5
- Affected:
- up to 19.1.5
- Fixed in:
- 19.1.5.1
- Disclosed:
- Dec 5, 2022
CVE-2022-4159 on NVD →
Contest Gallery <= 19.1.5 - Authenticated (Author+) SQL Injection via upload[]
high
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.5 due to insufficient escaping on the user supplied upload[] parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level privil...
- CVSS:
- 7.5
- Affected:
- up to 19.1.5
- Fixed in:
- 19.1.5.1
- Disclosed:
- Dec 5, 2022
CVE-2022-4153 on NVD →
Contest Gallery Pro <= 19.1.4.1 - Authenticated (Administrator+) SQL Injection via wp_user_id
medium
The Contest Gallery Pro plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied wp_user_id parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-leve...
- CVSS:
- 6.6
- Affected:
- up to 19.1.4.1
- Fixed in:
- 19.1.5
- Disclosed:
- Dec 5, 2022
CVE-2022-4154 on NVD →
Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_activate and cg_deactivate
high
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied cg_activate and cg_deactivate parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers,...
- CVSS:
- 7.5
- Affected:
- up to 19.1.4.1
- Fixed in:
- 19.1.5
- Disclosed:
- Nov 29, 2022
CVE-2022-4163 on NVD →
Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via option_id
high
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 19.1.4.1 due to insufficient escaping on the user supplied option_id parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with author-level pri...
- CVSS:
- 7.5
- Affected:
- up to 19.1.4.1
- Fixed in:
- 19.1.5
- Disclosed:
- Nov 29, 2022
CVE-2022-4151 on NVD →