Medium 5.3
2026-02-03< 2.1.1
CVE-2026-25023
Minimum safe version
2.1.1
Update to 2.1.1 or later to address 7 fixable vulnerabilities
CVE-2026-25023
WordPress Run Contests, Raffles, and Giveaways plugin <= 2.1.1 - Reflected Cross Site Scripting (XSS) vulnerability
CVE-2024-11456
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Run Contests, Raffles, and Giveaways with ContestsWP Plugin < 1.9.8 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Run Contests, Raffles, and Giveaways with ContestsWP plugin <= 1.7.8 - Sensitive Information Disclosure vulnerability
WordPress Run Contests, Raffles, and Giveaways with ContestsWP plugin <= 1.7.8 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability