CVE-2022-4158: Contest Gallery < 19.1.5 - Unauthenticated SQL Injection
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cgFields POST parameter before concatenating it to an SQL query in users-registry-check-registering-and-login.php. This may allow malicious visitors to leak sensitive information from the site's database.
Affected Software
Event History
Frequently Asked Questions
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2022-4158.
What is the affected software?
The affected software is Contest Gallery WordPress plugin before 19.1.5.1 and Contest Gallery Pro WordPress plugin before 19.1.5.1.
What is the severity of CVE-2022-4158?
The severity of CVE-2022-4158 is high with a value of 7.5.
How can this vulnerability be exploited?
This vulnerability can be exploited by malicious visitors leaking sensitive information.
Is there a fix available for this vulnerability?
Yes, the fix for this vulnerability is to update to Contest Gallery WordPress plugin version 19.1.5.1 or Contest Gallery Pro WordPress plugin version 19.1.5.1.