CVE-2022-4165: Contest Gallery < 19.1.5 - Author+ SQL Injection
The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cgorder POST parameter before concatenating it to an SQL query in order-custom-fields-with-and-without-search.php. This may allow malicious users with at least author privilege to leak sensitive information from the site's database.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-4165?
CVE-2022-4165 is a vulnerability in the Contest Gallery and Contest Gallery Pro WordPress plugins that allows malicious users to execute SQL queries.
What is the severity of CVE-2022-4165?
CVE-2022-4165 has a severity rating of medium with a CVSS score of 6.5.
How does CVE-2022-4165 affect the Contest Gallery WordPress plugin?
CVE-2022-4165 affects Contest Gallery WordPress plugin versions up to exclusive version 19.1.5.1.
How does CVE-2022-4165 affect the Contest Gallery Pro WordPress plugin?
CVE-2022-4165 affects Contest Gallery Pro WordPress plugin versions up to exclusive version 19.1.5.1.
How can I fix CVE-2022-4165 in the Contest Gallery and Contest Gallery Pro plugins?
To fix CVE-2022-4165, it is recommended to update the Contest Gallery and Contest Gallery Pro WordPress plugins to version 19.1.5.1 or later.