First published: Wed Mar 27 2024(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Contest Gallery.This issue affects Contest Gallery: from n/a through 21.3.2.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Contest Gallery | <=21.3.2 | |
Contest Gallery | >n/a<=21.3.2 |
Update to 21.3.2.1 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-30238 is classified as a SQL Injection vulnerability affecting the Contest Gallery plugin.
To fix CVE-2024-30238, upgrade the Contest Gallery plugin to version 21.3.3 or later.
CVE-2024-30238 affects the Contest Gallery plugin for WordPress, specifically versions from n/a to 21.3.2.
CVE-2024-30238 is an SQL Injection vulnerability due to improper neutralization of special elements in SQL commands.
Exploiting CVE-2024-30238 could allow attackers to manipulate database queries and potentially gain unauthorized access to sensitive data.