CVE-2022-36394: WordPress Contest Gallery plugin <= 17.0.4 - Authenticated SQL Injection (SQLi) vulnerability
Published Aug 23, 2022
·Updated
Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at WordPress.
Affected Software
1 affected component
contest-gallery Contest Gallery Wordpress<=17.0.4
Remediation
Information
Update to 17.0.5 or higher version.
Event History
Aug 23, 2022
CVE Published
via MITRE·03:47 PM
Data Sourced
via MITRE·03:47 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-36394?
CVE-2022-36394 is an authenticated SQL Injection (SQLi) vulnerability in the Contest Gallery plugin <= 17.0.4 at WordPress.
2
What is the severity of CVE-2022-36394?
The severity of CVE-2022-36394 is high with a CVSS score of 8.8.
3
How does CVE-2022-36394 affect Contest Gallery plugin?
CVE-2022-36394 affects Contest Gallery plugin version 17.0.4 or earlier.
4
What is the Common Weakness Enumeration (CWE) of CVE-2022-36394?
The Common Weakness Enumeration (CWE) of CVE-2022-36394 is CWE-89 (SQL Injection).
5
How can I fix the authenticated SQL Injection (SQLi) vulnerability in Contest Gallery plugin?
To fix the authenticated SQL Injection (SQLi) vulnerability in Contest Gallery plugin, upgrade to version 17.0.5 or later.