Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 60 vulnerability records associated with Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe, published between 2019 and 2026.

Dataset last synchronized: 2026-08-02 09:41:47 UTC

At a glance

Security Snapshot

60Total records
5Critical
27High
28Medium
0Low
0Informational
60Patched records
0Currently marked unpatched
2019-06-12First disclosure
2026-07-27Latest disclosure
57 of 60CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
201911 records
202122 records
20222020 records
202322 records
20241212 records
20251010 records
20261313 records

Severity Breakdown

SeverityRecordsShare
Critical58.3%
High2745%
Medium2846.7%

Vulnerability-Type Breakdown

SQL Injection

26 records43.3%

First: 2022. Latest: 2026.

Cross-Site Scripting

17 records28.3%

First: 2021. Latest: 2026.

Missing Authorization

5 records8.3%

First: 2024. Latest: 2026.

CSRF

4 records6.7%

First: 2019. Latest: 2025.

Information Disclosure

3 records5%

First: 2021. Latest: 2026.

Privilege Escalation

2 records3.3%

First: 2024. Latest: 2026.

Other

2 records3.3%

First: 2025. Latest: 2026.

Authentication Bypass

1 record1.7%

First: 2026. Latest: 2026.

Patch Status

Patched
60
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 30.0.7
  • 30.0.1
  • 30.0.3
  • 28.1.7
  • 29.0.0
  • 28.1.6
  • 28.1.3
  • 28.1.2.2
  • 28.1.5
  • 28.1.2
  • 28.0.3
  • 28.0.1
  • 28.0.0
  • 27.0.3
  • 26.1.1
  • 26.0.7
  • 26.0.9
  • 26.0.1
  • 25.1.2
  • 24.0.4
  • 24.0.8
  • 23.1.3
  • 21.3.6
  • 21.3.5
  • 21.3.2.1
  • 21.3.1
  • 21.2.9
  • 21.2.8.1
  • 21.1.2.1
  • 19.1.5.1
  • 19.1.5
  • 17.0.5
  • 13.1.0.6
  • 14.0.0
  • 13.1.0.7
  • 10.4.5

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-24.0.3Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 24.0.3 - Unauthenticated SQL InjectionNovember 4, 202424.0.4Critical
*-23.1.2Contest Gallery <= 23.1.2 - Unauthenticated Information ExposureAugust 16, 202423.1.3Medium
*-23.1.2Contest Gallery <= 23.1.2 - Unauthenticated Stored Cross-Site ScriptingJuly 24, 202423.1.3Medium
*-21.3.4Contest Gallery <= 21.3.4 - Authenticated (Author+) Arbitrary File DeletionApril 22, 202421.3.5Medium
*-21.3.5Contest Gallery <= 21.3.5 - Reflected Cross-Site ScriptingMarch 28, 202421.3.6Medium
*-21.3.4Photos and Files Contest Gallery <= 21.3.4 - Authenticated (Contributor+) SQL InjectionMarch 26, 202421.3.5Critical
*-21.3.2Photos and Files Contest Gallery <= 21.3.2 - Authenticated (Contributor+) SQL InjectionMarch 26, 202421.3.2.1Critical
*-21.3.0Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordPress <= 21.3.0 - Authenticated (Author+) Stored Cross-Site ScriptingFebruary 14, 202421.3.1Medium
*-21.2.8.4Contest Gallery <= 21.2.8.4 - Cross-Site Request ForgeryFebruary 5, 202421.2.9Medium
*-21.2.8.4Contest Gallery <= 21.2.8.4 - Cross-Site Request ForgeryJanuary 9, 202421.2.9Medium
[*, 21.2.8.1)Contest Gallery < 21.2.8.1 - Unauthenticated Stored Cross-Site Scripting via headersOctober 10, 202321.2.8.1Medium
*-21.1.2Contest Gallery <= 21.1.2 - Reflected Cross-Site ScriptingMarch 27, 202321.1.2.1Medium
*-19.1.4.1Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via addCountSDecember 5, 202219.1.5High
*-19.1.5Contest Gallery (Pro) <= 19.1.5 - SQL Injection via option_idDecember 5, 202219.1.5.1High
*-19.1.5Contest Gallery <= 19.1.5 - Authenticated (Author+) SQL Injection via upload[]December 5, 202219.1.5.1High
*-19.1.5Contest Gallery <= 19.1.5 - Authenticated (Author+) SQL Injection via cg_idDecember 5, 202219.1.5.1High
*-19.1.4.1Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_rowDecember 5, 202219.1.5High
*-19.1.4.1Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_orderDecember 5, 202219.1.5High
*-19.1.4.1Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via option_id GETDecember 5, 202219.1.5High
*-19.1.4.1Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_copy_startDecember 5, 202219.1.5High
*-19.1.4.1Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_copy_idDecember 5, 202219.1.5High
*-19.1.4.1Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_multiple_files_for_postDecember 5, 202219.1.5High
*-19.1.4.1Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via wp_user_idDecember 5, 202219.1.5High
*-19.1.4.1Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_option_idDecember 5, 202219.1.5High
*-19.1.5Contest Gallery <= 19.1.5 - Unauthenticated SQL Injection via user_idDecember 5, 202219.1.5.1High

Selected source records

Latest Records

HighCVE-2026-65447

Contest Gallery <= 30.0.6 - Unauthenticated Stored Cross-Site Scripting

Published: July 27, 2026

Affected versions
*-30.0.6
Patched versions
30.0.7
Original Wordfence record
MediumCVE-2026-57662

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 30.0.0 - Authenticated (Contributor+) SQL Injection

Published: June 26, 2026

Affected versions
*-30.0.0
Patched versions
30.0.1
Original Wordfence record
HighCVE-2026-12165

Contest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' Parameter

Published: June 16, 2026

Affected versions
*-30.0.2
Patched versions
30.0.3
Original Wordfence record
HighCVE-2026-8912

Contest Gallery <= 28.1.6 - Unauthenticated SQL Injection

Published: May 18, 2026

Affected versions
*-28.1.6
Patched versions
28.1.7
Original Wordfence record
MediumCVE-2026-42657

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.7 - Missing Authorization

Published: April 29, 2026

Affected versions
*-28.1.7
Patched versions
29.0.0
Original Wordfence record
MediumCVE-2026-42656

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting

Published: April 29, 2026

Affected versions
*-28.1.6
Patched versions
29.0.0
Original Wordfence record
MediumCVE-2026-42660

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.7 - Authenticated (Subscriber+) Sensitive Information Exposure

Published: April 29, 2026

Affected versions
*-28.1.7
Patched versions
29.0.0
Original Wordfence record
HighCVE-2026-40771

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.6 - Unauthenticated SQL Injection

Published: April 21, 2026

Affected versions
*-28.1.6
Patched versions
28.1.7
Original Wordfence record

Highest-Severity Records

CriticalCVE-2024-30238

Photos and Files Contest Gallery <= 21.3.2 - Authenticated (Contributor+) SQL Injection

Published: March 26, 2024

Affected versions
*-21.3.2
Patched versions
21.3.2.1
Original Wordfence record
CriticalCVE-2024-30236

Photos and Files Contest Gallery <= 21.3.4 - Authenticated (Contributor+) SQL Injection

Published: March 26, 2024

Affected versions
*-21.3.4
Patched versions
21.3.5
Original Wordfence record
CriticalCVE-2024-11103

Contest Gallery <= 24.0.7 - Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover

Published: November 27, 2024

Affected versions
*-24.0.7
Patched versions
24.0.8
Original Wordfence record
CriticalCVE-2021-24915

Contest Gallery – Photo Contest Plugin for WordPress <= 13.1.0.5 - SQL Injection

Published: April 13, 2022

Affected versions
*-13.1.0.5
Patched versions
13.1.0.6
Original Wordfence record
CriticalCVE-2024-10687

Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 24.0.3 - Unauthenticated SQL Injection

Published: November 4, 2024

Affected versions
*-24.0.3
Patched versions
24.0.4
Original Wordfence record
HighCVE-2026-12165

Contest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' Parameter

Published: June 16, 2026

Affected versions
*-30.0.2
Patched versions
30.0.3
Original Wordfence record
HighCVE-2022-4150

Contest Gallery (Pro) <= 19.1.5 - SQL Injection via option_id

Published: December 5, 2022

Affected versions
*-19.1.5
Patched versions
19.1.5.1
Affected versions
*-19.1.5
Patched versions
19.1.5.1
Original Wordfence record
HighCVE-2022-36394

Contest Gallery <= 17.0.4 - Authenticated (Author+) SQL Injection

Published: August 9, 2022

Affected versions
*-17.0.4
Patched versions
17.0.5
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory