First published: Mon Dec 26 2022(Updated: )
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_row POST parameter before concatenating it to an SQL query in 3_row-order.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Contest-gallery Contest Gallery | <19.1.5.1 | |
Contest-gallery Contest Gallery | <19.1.5.1 | |
<19.1.5.1 | ||
<19.1.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4162 is a vulnerability in the Contest Gallery WordPress plugin and Contest Gallery Pro WordPress plugin that allows malicious users with at least author privilege to leak sensitive information.
The Contest Gallery WordPress plugin before version 19.1.5.1 and Contest Gallery Pro WordPress plugin before version 19.1.5.1 are affected by CVE-2022-4162.
The severity of CVE-2022-4162 is medium with a CVSS score of 6.5.
CVE-2022-4162 can be exploited by malicious users with at least author privilege to leak sensitive information.
Yes, upgrading to version 19.1.5.1 or later of the Contest Gallery WordPress plugin and Contest Gallery Pro WordPress plugin will fix CVE-2022-4162.