CVE-2022-4150: Contest Gallery < 19.1.5 - Author+ SQL Injection
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the optionid POST parameter before concatenating it to an SQL query in order-custom-fields-with-and-without-search.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-4150?
CVE-2022-4150 is a vulnerability in the Contest Gallery WordPress plugin and Contest Gallery Pro WordPress plugin that allows malicious users to execute SQL queries.
What is the severity of CVE-2022-4150?
The severity of CVE-2022-4150 is medium.
How does CVE-2022-4150 impact the affected software?
CVE-2022-4150 allows malicious users with author privileges to execute SQL queries.
How do I fix CVE-2022-4150?
To fix CVE-2022-4150, update the Contest Gallery WordPress plugin and Contest Gallery Pro WordPress plugin to version 19.1.5.1 or later.
Are there any references for CVE-2022-4150?
Yes, you can find more information about CVE-2022-4150 at the following references: [reference1](https://bulletin.iese.de/post/contest-gallery_19-1-4-1_13) and [reference2](https://wpscan.com/vulnerability/d5d39138-a216-46cd-9e5f-fc706a2c93da).