First published: Tue Aug 23 2022(Updated: )
Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at WordPress.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Contest-gallery Contest Gallery | <=17.0.4 |
Update to 17.0.5 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36394 is an authenticated SQL Injection (SQLi) vulnerability in the Contest Gallery plugin <= 17.0.4 at WordPress.
The severity of CVE-2022-36394 is high with a CVSS score of 8.8.
CVE-2022-36394 affects Contest Gallery plugin version 17.0.4 or earlier.
The Common Weakness Enumeration (CWE) of CVE-2022-36394 is CWE-89 (SQL Injection).
To fix the authenticated SQL Injection (SQLi) vulnerability in Contest Gallery plugin, upgrade to version 17.0.5 or later.