Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 60 vulnerability records associated with Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe, published between 2019 and 2026.

Dataset last synchronized: 2026-08-02 09:41:47 UTC

At a glance

Security Snapshot

60Total records
5Critical
27High
28Medium
0Low
0Informational
60Patched records
0Currently marked unpatched
2019-06-12First disclosure
2026-07-27Latest disclosure
57 of 60CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
201911 records
202122 records
20222020 records
202322 records
20241212 records
20251010 records
20261313 records

Severity Breakdown

SeverityRecordsShare
Critical58.3%
High2745%
Medium2846.7%

Vulnerability-Type Breakdown

SQL Injection

26 records43.3%

First: 2022. Latest: 2026.

Cross-Site Scripting

17 records28.3%

First: 2021. Latest: 2026.

Missing Authorization

5 records8.3%

First: 2024. Latest: 2026.

CSRF

4 records6.7%

First: 2019. Latest: 2025.

Information Disclosure

3 records5%

First: 2021. Latest: 2026.

Privilege Escalation

2 records3.3%

First: 2024. Latest: 2026.

Other

2 records3.3%

First: 2025. Latest: 2026.

Authentication Bypass

1 record1.7%

First: 2026. Latest: 2026.

Patch Status

Patched
60
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 30.0.7
  • 30.0.1
  • 30.0.3
  • 28.1.7
  • 29.0.0
  • 28.1.6
  • 28.1.3
  • 28.1.2.2
  • 28.1.5
  • 28.1.2
  • 28.0.3
  • 28.0.1
  • 28.0.0
  • 27.0.3
  • 26.1.1
  • 26.0.7
  • 26.0.9
  • 26.0.1
  • 25.1.2
  • 24.0.4
  • 24.0.8
  • 23.1.3
  • 21.3.6
  • 21.3.5
  • 21.3.2.1
  • 21.3.1
  • 21.2.9
  • 21.2.8.1
  • 21.1.2.1
  • 19.1.5.1
  • 19.1.5
  • 17.0.5
  • 13.1.0.6
  • 14.0.0
  • 13.1.0.7
  • 10.4.5

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-30.0.6Contest Gallery <= 30.0.6 - Unauthenticated Stored Cross-Site ScriptingJuly 27, 202630.0.7High
*-30.0.0Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 30.0.0 - Authenticated (Contributor+) SQL InjectionJune 26, 202630.0.1Medium
*-30.0.2Contest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' ParameterJune 16, 202630.0.3High
*-28.1.6Contest Gallery <= 28.1.6 - Unauthenticated SQL InjectionMay 18, 202628.1.7High
*-28.1.7Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.7 - Authenticated (Subscriber+) Sensitive Information ExposureApril 29, 202629.0.0Medium
*-28.1.6Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.6 - Authenticated (Subscriber+) Stored Cross-Site ScriptingApril 29, 202629.0.0Medium
*-28.1.7Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.7 - Missing AuthorizationApril 29, 202629.0.0Medium
*-28.1.6Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.6 - Unauthenticated SQL InjectionApril 21, 202628.1.7High
*-28.1.5Contest Gallery <= 28.1.5 - Unauthenticated Privilege Escalation Admin Account Takeover via Registration Confirmation Email-to-ID Type ConfusionMarch 23, 202628.1.6High
*-28.1.2.2Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.2.2 - Missing AuthorizationMarch 23, 202628.1.3Medium
*-28.1.2.1Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.2.1 - Authenticated (Subscriber+) Server-Side Request ForgeryMarch 10, 202628.1.2.2Medium
*-28.1.4Contest Gallery <= 28.1.4 - Unauthenticated SQL InjectionMarch 2, 202628.1.5High
*-28.1.1Contest Gallery <= 28.1.1 - Missing AuthorizationJanuary 9, 202628.1.2Medium
*-28.0.2Contest Gallery <= 28.0.2 - Missing AuthorizationNovember 14, 202528.0.3Medium
*-28.0.0Contest Gallery <= 28.0.0 - Cross-Site Request ForgeryOctober 12, 202528.0.1Medium
*-27.0.3Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.3 - Unauthenticated CSV InjectionOctober 10, 202528.0.0Medium
*-27.0.2Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.2 - Authenticated (Author+) Stored Cross-Site ScriptingOctober 3, 202527.0.3Medium
*-26.1.0Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI <= 26.1.0 - Unauthenticated Stored Cross-Site ScriptingJuly 31, 202526.1.1High
*-26.0.6Contest Gallery <= 26.0.6 - Reflected Cross-Site ScriptingJuly 11, 202526.0.7Medium
*-26.0.8Contest Gallery <= 26.0.8 - Authenticated (Author+) Stored Cross-Site ScriptingJuly 10, 202526.0.9Medium
*-26.0.6Contest Gallery <= 26.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id ParameterMay 7, 202526.0.7Medium
*-26.0.0.1Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 26.0.0.1 - Unauthenticated Stored Cross-Site ScriptingFebruary 27, 202526.0.1High
*-25.1.0Contest Gallery <= 25.1.0 - Authenticated (Author+) SQL InjectionJanuary 31, 202525.1.2Medium
*-24.0.3Contest Gallery <= 24.0.3 - Authenticated (Author+) Stored Cross-Site ScriptingDecember 30, 202424.0.4Medium
*-24.0.7Contest Gallery <= 24.0.7 - Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account TakeoverNovember 27, 202424.0.8Critical

Selected source records

Latest Records

HighCVE-2026-65447

Contest Gallery <= 30.0.6 - Unauthenticated Stored Cross-Site Scripting

Published: July 27, 2026

Affected versions
*-30.0.6
Patched versions
30.0.7
Original Wordfence record
MediumCVE-2026-57662

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 30.0.0 - Authenticated (Contributor+) SQL Injection

Published: June 26, 2026

Affected versions
*-30.0.0
Patched versions
30.0.1
Original Wordfence record
HighCVE-2026-12165

Contest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' Parameter

Published: June 16, 2026

Affected versions
*-30.0.2
Patched versions
30.0.3
Original Wordfence record
HighCVE-2026-8912

Contest Gallery <= 28.1.6 - Unauthenticated SQL Injection

Published: May 18, 2026

Affected versions
*-28.1.6
Patched versions
28.1.7
Original Wordfence record
MediumCVE-2026-42657

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.7 - Missing Authorization

Published: April 29, 2026

Affected versions
*-28.1.7
Patched versions
29.0.0
Original Wordfence record
MediumCVE-2026-42656

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting

Published: April 29, 2026

Affected versions
*-28.1.6
Patched versions
29.0.0
Original Wordfence record
MediumCVE-2026-42660

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.7 - Authenticated (Subscriber+) Sensitive Information Exposure

Published: April 29, 2026

Affected versions
*-28.1.7
Patched versions
29.0.0
Original Wordfence record
HighCVE-2026-40771

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.6 - Unauthenticated SQL Injection

Published: April 21, 2026

Affected versions
*-28.1.6
Patched versions
28.1.7
Original Wordfence record

Highest-Severity Records

CriticalCVE-2024-30238

Photos and Files Contest Gallery <= 21.3.2 - Authenticated (Contributor+) SQL Injection

Published: March 26, 2024

Affected versions
*-21.3.2
Patched versions
21.3.2.1
Original Wordfence record
CriticalCVE-2024-30236

Photos and Files Contest Gallery <= 21.3.4 - Authenticated (Contributor+) SQL Injection

Published: March 26, 2024

Affected versions
*-21.3.4
Patched versions
21.3.5
Original Wordfence record
CriticalCVE-2024-11103

Contest Gallery <= 24.0.7 - Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover

Published: November 27, 2024

Affected versions
*-24.0.7
Patched versions
24.0.8
Original Wordfence record
CriticalCVE-2021-24915

Contest Gallery – Photo Contest Plugin for WordPress <= 13.1.0.5 - SQL Injection

Published: April 13, 2022

Affected versions
*-13.1.0.5
Patched versions
13.1.0.6
Original Wordfence record
CriticalCVE-2024-10687

Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 24.0.3 - Unauthenticated SQL Injection

Published: November 4, 2024

Affected versions
*-24.0.3
Patched versions
24.0.4
Original Wordfence record
HighCVE-2026-12165

Contest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' Parameter

Published: June 16, 2026

Affected versions
*-30.0.2
Patched versions
30.0.3
Original Wordfence record
HighCVE-2022-4150

Contest Gallery (Pro) <= 19.1.5 - SQL Injection via option_id

Published: December 5, 2022

Affected versions
*-19.1.5
Patched versions
19.1.5.1
Affected versions
*-19.1.5
Patched versions
19.1.5.1
Original Wordfence record
HighCVE-2022-36394

Contest Gallery <= 17.0.4 - Authenticated (Author+) SQL Injection

Published: August 9, 2022

Affected versions
*-17.0.4
Patched versions
17.0.5
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory