CVE-2022-4151: Contest Gallery < 19.1.5 - Admin+ SQL Injection
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the optionid GET parameter before concatenating it to an SQL query in export-images-data.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-4151?
CVE-2022-4151 is a vulnerability in the Contest Gallery WordPress plugin before version 19.1.5.1 and the Contest Gallery Pro WordPress plugin before version 19.1.5.1.
What is the severity of CVE-2022-4151?
The severity of CVE-2022-4151 is medium with a CVSSv3 base score of 6.5.
How does CVE-2022-4151 affect Contest Gallery plugins?
CVE-2022-4151 affects the Contest Gallery WordPress plugin before version 19.1.5.1 and the Contest Gallery Pro WordPress plugin before version 19.1.5.1.
What is the CWE category of CVE-2022-4151?
CVE-2022-4151 is categorized as CWE-89, which is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection').
How can I fix CVE-2022-4151?
To fix CVE-2022-4151, update the Contest Gallery WordPress plugin to version 19.1.5.1 or higher, and the Contest Gallery Pro WordPress plugin to version 19.1.5.1 or higher.