CVE-2025-22693: WordPress Contest Gallery plugin <= 25.1.0 - SQL Injection vulnerability
Published Feb 3, 2025
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery allows SQL Injection.This issue affects Contest Gallery: from n/a through <= 25.1.0.
Affected Software
2 affected components
Contest Gallery Contest Gallery>=n/a, <=25.1.0
contest-gallery Contest Gallery Wordpress<25.1.2
Event History
Feb 3, 2025
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-22693?
CVE-2025-22693 is classified as a high-severity SQL Injection vulnerability.
2
How do I fix CVE-2025-22693?
To mitigate CVE-2025-22693, upgrade Contest Gallery to version 25.1.0 or later.
3
What software is affected by CVE-2025-22693?
CVE-2025-22693 affects the Contest Gallery plugin versions from n/a to 25.1.0.
4
What are the risks associated with CVE-2025-22693?
Exploiting CVE-2025-22693 can allow attackers to execute arbitrary SQL commands on the database.
5
When was CVE-2025-22693 published?
CVE-2025-22693 was published in 2025.