Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.7 - Missing Authorization
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe
Minimum safe version
29.0.0
Update to 29.0.0 or later to address 58 fixable vulnerabilities
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.7 - Authenticated (Subscriber+) Sensitive Information Exposure
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.6 - Unauthenticated SQL Injection
Contest Gallery <= 28.1.4 - Unauthenticated SQL Injection
Contest Gallery <= 28.1.5 - Unauthenticated Privilege Escalation Admin Account Takeover via Registration Confirmation Email-to-ID Type Confusion
CVE-2026-25035
CVE-2026-24964
CVE-2026-24965
CVE-2025-12849
CVE-2025-62950
CVE-2025-11254
CVE-2025-10383
Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI <= 26.1.0 - Unauthenticated Stored Cross-Site Scripting
CVE-2025-48291
Contest Gallery <= 26.0.8 - Authenticated (Author+) Stored Cross-Site Scripting
Contest Gallery <= 26.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter
Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 26.0.0.1 - Unauthenticated Stored Cross-Site Scripting
CVE-2025-22693
WordPress Contest Gallery Plugin <= 24.0.3 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-11103
CVE-2024-10687
CVE-2024-43283
CVE-2024-39631
CVE-2024-32778
CVE-2024-30428
CVE-2024-30236
CVE-2024-30238
CVE-2024-1487
CVE-2024-24887
Contest Gallery <= 21.2.8.4 - Cross-Site Request Forgery
CVE-2023-5307
CVE-2023-28784
CVE-2022-4150
Contest Gallery < 13.1.0.7 - Authenticated Email Address Disclosure
Contest Gallery – Files Upload and Contest Plugin for WordPress <= 17.0.4 - Admin+ SQL Injection
CVE-2022-4163
CVE-2022-4151
CVE-2022-4166
CVE-2022-4153
CVE-2022-4159
CVE-2022-4162
CVE-2022-4165
CVE-2022-4152
CVE-2022-4161
CVE-2022-4160
CVE-2022-4164
CVE-2022-4155
CVE-2022-4157
CVE-2022-4156
CVE-2022-4158
CVE-2022-45848
Contest Gallery < 13.1.0.7 - Subscriber+ Email Address Disclosure
CVE-2022-36394
WordPress Contest Gallery plugin <= 13.1.0.6 - Email Address Disclosure vulnerability
CVE-2022-27853
WordPress Contest Gallery plugin <= 10.4.4 - Cross-Site Request Forgery (CSRF) vulnerability
Contest Gallery – Photo Contest Plugin for WordPress <= 13.1.0.5 - SQL Injection