Extension WordPress

Vulnérabilités Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Cette page rassemble les failles publiées pour Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe, leurs plages de versions affectées et les correctifs signalés dans la base locale.

59Vulnérabilités
5Critiques
59Avec correctif
9,9CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

59 fiches

CVE-2026-57662 Moyenne · 6,5
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 30.0.0 – Authenticated (Contributor+) SQL Injection

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 30.0.0 due to insufficient escaping on the user supplied parameter…

Versions affectées

*-30.0.0

Correctif

30.0.1

Publication

26/06/2026

CVE-2026-12165 Élevée · 8,8
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 30.0.2 – Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' Parameter

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 30.0.2 via the `RegistryUserRole` parameter. This is due to…

Versions affectées

*-30.0.2

Correctif

30.0.3

Publication

16/06/2026

CVE-2026-8912 Élevée · 7,5
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 28.1.6 – Unauthenticated SQL Injection

The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to, and including, 28.1.6. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…

Versions affectées

*-28.1.6

Correctif

28.1.7

Publication

18/05/2026

CVE-2026-42657 Moyenne · 5,3
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.7 – Missing Authorization

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including,…

Versions affectées

*-28.1.7

Correctif

29.0.0

Publication

29/04/2026

CVE-2026-42660 Moyenne · 4,3
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.7 – Authenticated (Subscriber+) Sensitive Information Exposure

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 28.1.7. This makes it possible for authenticated attackers,…

Versions affectées

*-28.1.7

Correctif

29.0.0

Publication

29/04/2026

CVE-2026-42656 Moyenne · 6,4
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.6 – Authenticated (Subscriber+) Stored Cross-Site Scripting

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 28.1.6 due to insufficient input sanitization and output escaping.…

Versions affectées

*-28.1.6

Correctif

29.0.0

Publication

29/04/2026

CVE-2026-40771 Élevée · 7,5
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.6 – Unauthenticated SQL Injection

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 28.1.6 due to insufficient escaping on the user supplied parameter…

Versions affectées

*-28.1.6

Correctif

28.1.7

Publication

21/04/2026

CVE-2026-4021 Élevée · 8,1
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 28.1.5 – Unauthenticated Privilege Escalation Admin Account Takeover via Registration Confirmation Email-to-ID Type Confusion

The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in all versions up to, and including, 28.1.5. This is due to the email confirmation handler in `users-registry-check-after-email-or-pin-confirmation.php` using the user's…

Versions affectées

*-28.1.5

Correctif

28.1.6

Publication

23/03/2026

CVE-2026-25035 Moyenne · 5,3
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.2.2 – Missing Authorization

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including,…

Versions affectées

*-28.1.2.2

Correctif

28.1.3

Publication

23/03/2026

CVE-2026-24964 Moyenne · 6,4
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.2.1 – Authenticated (Subscriber+) Server-Side Request Forgery

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 28.1.2.1. This makes it possible for authenticated attackers,…

Versions affectées

*-28.1.2.1

Correctif

28.1.2.2

Publication

10/03/2026

CVE-2026-3180 Élevée · 7,5
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 28.1.4 – Unauthenticated SQL Injection

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to blind SQL Injection via the ‘cgLostPasswordEmail’ and the ’cgl_mail’ parameter in all versions up to, and including, 28.1.4…

Versions affectées

*-28.1.4

Correctif

28.1.5

Publication

02/03/2026

CVE-2025-12849 Moyenne · 5,3
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 28.0.2 – Missing Authorization

The Contest Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 28.0.2. This is due to the plugin registering the `cg_check_wp_admin_upload_v10` AJAX action for both authenticated and unauthenticated users without implementing…

Versions affectées

*-28.0.2

Correctif

28.0.3

Publication

14/11/2025

CVE-2025-62950 Moyenne · 4,3
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 28.0.0 – Cross-Site Request Forgery

The Contest Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 28.0.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers…

Versions affectées

*-28.0.0

Correctif

28.0.1

Publication

12/10/2025

CVE-2025-11254 Moyenne · 4,3
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.3 – Unauthenticated CSV Injection

The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 27.0.3 via gallery submissions. This makes it possible for unauthenticated attackers…

Versions affectées

*-27.0.3

Correctif

28.0.0

Publication

10/10/2025

CVE-2025-10383 Moyenne · 6,4
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.2 – Authenticated (Author+) Stored Cross-Site Scripting

The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple form field parameters in all versions up to, and including, 27.0.2. This is due to…

Versions affectées

*-27.0.2

Correctif

27.0.3

Publication

03/10/2025

CVE-2025-7725 Élevée · 7,2
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI <= 26.1.0 – Unauthenticated Stored Cross-Site Scripting

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment feature in all versions…

Versions affectées

*-26.1.0

Correctif

26.1.1

Publication

31/07/2025

CVE-2025-48291 Moyenne · 6,1
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 26.0.6 – Reflected Cross-Site Scripting

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including,…

Versions affectées

*-26.0.6

Correctif

26.0.7

Publication

11/07/2025

CVE-2025-6716 Moyenne · 6,4
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 26.0.8 – Authenticated (Author+) Stored Cross-Site Scripting

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'upload[1][title]' parameter in all versions…

Versions affectées

*-26.0.8

Correctif

26.0.9

Publication

10/07/2025

CVE-2025-3862 Moyenne · 6,4
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Contest Gallery <= 26.0.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter

Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 26.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,…

Versions affectées

*-26.0.6

Correctif

26.0.7

Publication

08/05/2025

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités