SQL Injection
26 records43.3%First: 2022. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 60 vulnerability records associated with Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe, published between 2019 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2019 | 1 | |
| 2021 | 2 | |
| 2022 | 20 | |
| 2023 | 2 | |
| 2024 | 12 | |
| 2025 | 10 | |
| 2026 | 13 |
| Severity | Records | Share |
|---|---|---|
| Critical | 5 | 8.3% |
| High | 27 | 45% |
| Medium | 28 | 46.7% |
First: 2022. Latest: 2026.
First: 2021. Latest: 2026.
First: 2024. Latest: 2026.
First: 2019. Latest: 2025.
First: 2021. Latest: 2026.
First: 2024. Latest: 2026.
First: 2025. Latest: 2026.
First: 2026. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
30.0.730.0.130.0.328.1.729.0.028.1.628.1.328.1.2.228.1.528.1.228.0.328.0.128.0.027.0.326.1.126.0.726.0.926.0.125.1.224.0.424.0.823.1.321.3.621.3.521.3.2.121.3.121.2.921.2.8.121.1.2.119.1.5.119.1.517.0.513.1.0.614.0.013.1.0.710.4.5Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-30.0.6 | Contest Gallery <= 30.0.6 - Unauthenticated Stored Cross-Site Scripting | July 27, 2026 | 30.0.7 | High |
*-30.0.0 | Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 30.0.0 - Authenticated (Contributor+) SQL Injection | June 26, 2026 | 30.0.1 | Medium |
*-30.0.2 | Contest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' Parameter | June 16, 2026 | 30.0.3 | High |
*-28.1.6 | Contest Gallery <= 28.1.6 - Unauthenticated SQL Injection | May 18, 2026 | 28.1.7 | High |
*-28.1.7 | Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.7 - Authenticated (Subscriber+) Sensitive Information Exposure | April 29, 2026 | 29.0.0 | Medium |
*-28.1.6 | Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting | April 29, 2026 | 29.0.0 | Medium |
*-28.1.7 | Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.7 - Missing Authorization | April 29, 2026 | 29.0.0 | Medium |
*-28.1.6 | Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.6 - Unauthenticated SQL Injection | April 21, 2026 | 28.1.7 | High |
*-28.1.5 | Contest Gallery <= 28.1.5 - Unauthenticated Privilege Escalation Admin Account Takeover via Registration Confirmation Email-to-ID Type Confusion | March 23, 2026 | 28.1.6 | High |
*-28.1.2.2 | Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.2.2 - Missing Authorization | March 23, 2026 | 28.1.3 | Medium |
*-28.1.2.1 | Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.2.1 - Authenticated (Subscriber+) Server-Side Request Forgery | March 10, 2026 | 28.1.2.2 | Medium |
*-28.1.4 | Contest Gallery <= 28.1.4 - Unauthenticated SQL Injection | March 2, 2026 | 28.1.5 | High |
*-28.1.1 | Contest Gallery <= 28.1.1 - Missing Authorization | January 9, 2026 | 28.1.2 | Medium |
*-28.0.2 | Contest Gallery <= 28.0.2 - Missing Authorization | November 14, 2025 | 28.0.3 | Medium |
*-28.0.0 | Contest Gallery <= 28.0.0 - Cross-Site Request Forgery | October 12, 2025 | 28.0.1 | Medium |
*-27.0.3 | Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.3 - Unauthenticated CSV Injection | October 10, 2025 | 28.0.0 | Medium |
*-27.0.2 | Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.2 - Authenticated (Author+) Stored Cross-Site Scripting | October 3, 2025 | 27.0.3 | Medium |
*-26.1.0 | Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI <= 26.1.0 - Unauthenticated Stored Cross-Site Scripting | July 31, 2025 | 26.1.1 | High |
*-26.0.6 | Contest Gallery <= 26.0.6 - Reflected Cross-Site Scripting | July 11, 2025 | 26.0.7 | Medium |
*-26.0.8 | Contest Gallery <= 26.0.8 - Authenticated (Author+) Stored Cross-Site Scripting | July 10, 2025 | 26.0.9 | Medium |
*-26.0.6 | Contest Gallery <= 26.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter | May 7, 2025 | 26.0.7 | Medium |
*-26.0.0.1 | Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 26.0.0.1 - Unauthenticated Stored Cross-Site Scripting | February 27, 2025 | 26.0.1 | High |
*-25.1.0 | Contest Gallery <= 25.1.0 - Authenticated (Author+) SQL Injection | January 31, 2025 | 25.1.2 | Medium |
*-24.0.3 | Contest Gallery <= 24.0.3 - Authenticated (Author+) Stored Cross-Site Scripting | December 30, 2024 | 24.0.4 | Medium |
*-24.0.7 | Contest Gallery <= 24.0.7 - Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover | November 27, 2024 | 24.0.8 | Critical |
Selected source records
Published: July 27, 2026
Published: June 26, 2026
Published: June 16, 2026
Published: May 18, 2026
Published: April 29, 2026
Published: April 29, 2026
Published: April 29, 2026
Published: April 21, 2026
Published: March 26, 2024
Published: March 26, 2024
Published: November 27, 2024
Published: April 13, 2022
Published: November 4, 2024
Published: June 16, 2026
Published: December 5, 2022
Published: August 9, 2022
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.