CVE-2022-4152: Contest Gallery < 19.1.5 - Author+ SQL Injection
The Contest Gallery WordPress plugin before 19.1.5, Contest Gallery Pro WordPress plugin before 19.1.5 do not escape the optionid POST parameter before concatenating it to an SQL query in edit-options.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-4152?
CVE-2022-4152 is a vulnerability in the Contest Gallery and Contest Gallery Pro WordPress plugins that allows malicious users with at least author privileges to leak sensitive information.
What is the severity of CVE-2022-4152?
The severity of CVE-2022-4152 is medium (6.5).
How does CVE-2022-4152 affect the Contest Gallery WordPress plugin?
CVE-2022-4152 affects the Contest Gallery WordPress plugin versions up to and exclusive of 19.1.5.1.
How does CVE-2022-4152 affect the Contest Gallery Pro WordPress plugin?
CVE-2022-4152 affects the Contest Gallery Pro WordPress plugin versions up to and exclusive of 19.1.5.1.
How can I fix CVE-2022-4152?
To fix CVE-2022-4152, you should update the Contest Gallery and Contest Gallery Pro WordPress plugins to version 19.1.5.1 or later.