plugin

Photo Contest Vulnerabilities

4 known security issues reported for the Photo Contest WordPress plugin. Most recent disclosed Jul 1, 2023.

1 medium

Running Photo Contest on your site? Check whether your installed version is affected.

Scan your site free

Photo Gallery – Image Gallery [photo-contest] <= 1.0.6 (unfixed)

unknown

[en] The WordPress Photo Gallery – Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.6. This is due to missing or incorrect nonce validation on the load_images_thumbnail() and edit_gallery() functions. This makes it possible for unauthenticated attacker...

Affected:
up to 1.0.6
Fix:
No patched version reported
Disclosed:
Jul 1, 2023

CVE-2021-4384 on NVD →

Photo Gallery – Image Gallery [photo-contest] <= 1.0.8 (unfixed + closed)

unknown

Cross-Site Request Forgery (CSRF) vulnerability discovered by Jerome Bruandet (NinTechNet) in WordPress WordPress Photo Gallery – Image Gallery plugin (versions <= 1.0.8).

Affected:
up to 1.0.8
Fix:
No patched version reported
Disclosed:
Aug 16, 2021

WordPress Photo Gallery – Image Gallery <= 1.0.6 - Cross-Site Request Forgery Bypass

medium

The WordPress Photo Gallery – Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.6. This is due to missing or incorrect nonce validation on the load_images_thumbnail() and edit_gallery() functions. This makes it possible for unauthenticated attackers to...

CVSS:
4.3
Affected:
up to 1.0.6
Fix:
No patched version reported
Disclosed:
Jul 16, 2021

CVE-2021-4384 on NVD →

Photo Gallery – Image Gallery [photo-contest] <= 1.1.1 (unfixed + closed)

unknown

Multiple plugins are affected by CSRF issues due to a logic flaw in their CSRF checks, which could allow attackers to make users perform unwanted actions rucy &lt;= 0.4.4 wp-backgrounds-lite &lt;= 2.3 wp-security-questions &lt;= 1.0.5 photo-contest &lt;= 1.0.6 opal-estate &lt;= 1.6.11 rays-grid &lt;= 1.2.2

Affected:
up to 1.1.1
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database