PT-2024-16462 · WordPress · Contest Gallery
Khayal Farzaliyev
+1
·
Published
2024-11-05
·
Updated
2026-04-08
·
CVE-2024-10687
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Contest-Gallery plugin for WordPress versions prior to 24.0.1
Contest-Gallery plugin for WordPress version 24.0.1 is not affected according to some sources, but others indicate versions up to and including 24.0.3 are vulnerable. Therefore, considering all information, the most accurate representation is:
Contest-Gallery plugin for WordPress versions up to and including 24.0.3
Description
The Contest-Gallery plugin for WordPress is susceptible to time-based SQL Injection due to insufficient escaping on the user-supplied
collectedIds parameter and lack of sufficient preparation on the existing SQL query. This allows unauthenticated attackers to append additional SQL queries into already existing queries, potentially extracting sensitive information from the database. Exploitation could lead to unauthorized data access.Recommendations
Update to the latest version of the Contest-Gallery plugin for WordPress immediately to secure your site.
As a temporary workaround, consider restricting access to the plugin or disabling the
collectedIds parameter until a patch is applied, but the most effective solution is updating to a version beyond 24.0.3.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contest Gallery