SQL Injection
26 records43.3%First: 2022. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 60 vulnerability records associated with Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe, published between 2019 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2019 | 1 | |
| 2021 | 2 | |
| 2022 | 20 | |
| 2023 | 2 | |
| 2024 | 12 | |
| 2025 | 10 | |
| 2026 | 13 |
| Severity | Records | Share |
|---|---|---|
| Critical | 5 | 8.3% |
| High | 27 | 45% |
| Medium | 28 | 46.7% |
First: 2022. Latest: 2026.
First: 2021. Latest: 2026.
First: 2024. Latest: 2026.
First: 2019. Latest: 2025.
First: 2021. Latest: 2026.
First: 2024. Latest: 2026.
First: 2025. Latest: 2026.
First: 2026. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
30.0.730.0.130.0.328.1.729.0.028.1.628.1.328.1.2.228.1.528.1.228.0.328.0.128.0.027.0.326.1.126.0.726.0.926.0.125.1.224.0.424.0.823.1.321.3.621.3.521.3.2.121.3.121.2.921.2.8.121.1.2.119.1.5.119.1.517.0.513.1.0.614.0.013.1.0.710.4.5Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-24.0.3 | Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 24.0.3 - Unauthenticated SQL Injection | November 4, 2024 | 24.0.4 | Critical |
*-23.1.2 | Contest Gallery <= 23.1.2 - Unauthenticated Information Exposure | August 16, 2024 | 23.1.3 | Medium |
*-23.1.2 | Contest Gallery <= 23.1.2 - Unauthenticated Stored Cross-Site Scripting | July 24, 2024 | 23.1.3 | Medium |
*-21.3.4 | Contest Gallery <= 21.3.4 - Authenticated (Author+) Arbitrary File Deletion | April 22, 2024 | 21.3.5 | Medium |
*-21.3.5 | Contest Gallery <= 21.3.5 - Reflected Cross-Site Scripting | March 28, 2024 | 21.3.6 | Medium |
*-21.3.4 | Photos and Files Contest Gallery <= 21.3.4 - Authenticated (Contributor+) SQL Injection | March 26, 2024 | 21.3.5 | Critical |
*-21.3.2 | Photos and Files Contest Gallery <= 21.3.2 - Authenticated (Contributor+) SQL Injection | March 26, 2024 | 21.3.2.1 | Critical |
*-21.3.0 | Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordPress <= 21.3.0 - Authenticated (Author+) Stored Cross-Site Scripting | February 14, 2024 | 21.3.1 | Medium |
*-21.2.8.4 | Contest Gallery <= 21.2.8.4 - Cross-Site Request Forgery | February 5, 2024 | 21.2.9 | Medium |
*-21.2.8.4 | Contest Gallery <= 21.2.8.4 - Cross-Site Request Forgery | January 9, 2024 | 21.2.9 | Medium |
[*, 21.2.8.1) | Contest Gallery < 21.2.8.1 - Unauthenticated Stored Cross-Site Scripting via headers | October 10, 2023 | 21.2.8.1 | Medium |
*-21.1.2 | Contest Gallery <= 21.1.2 - Reflected Cross-Site Scripting | March 27, 2023 | 21.1.2.1 | Medium |
*-19.1.4.1 | Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via addCountS | December 5, 2022 | 19.1.5 | High |
*-19.1.5 | Contest Gallery (Pro) <= 19.1.5 - SQL Injection via option_id | December 5, 2022 | 19.1.5.1 | High |
*-19.1.5 | Contest Gallery <= 19.1.5 - Authenticated (Author+) SQL Injection via upload[] | December 5, 2022 | 19.1.5.1 | High |
*-19.1.5 | Contest Gallery <= 19.1.5 - Authenticated (Author+) SQL Injection via cg_id | December 5, 2022 | 19.1.5.1 | High |
*-19.1.4.1 | Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_row | December 5, 2022 | 19.1.5 | High |
*-19.1.4.1 | Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_order | December 5, 2022 | 19.1.5 | High |
*-19.1.4.1 | Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via option_id GET | December 5, 2022 | 19.1.5 | High |
*-19.1.4.1 | Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_copy_start | December 5, 2022 | 19.1.5 | High |
*-19.1.4.1 | Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_copy_id | December 5, 2022 | 19.1.5 | High |
*-19.1.4.1 | Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_multiple_files_for_post | December 5, 2022 | 19.1.5 | High |
*-19.1.4.1 | Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via wp_user_id | December 5, 2022 | 19.1.5 | High |
*-19.1.4.1 | Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_option_id | December 5, 2022 | 19.1.5 | High |
*-19.1.5 | Contest Gallery <= 19.1.5 - Unauthenticated SQL Injection via user_id | December 5, 2022 | 19.1.5.1 | High |
Selected source records
Published: July 27, 2026
Published: June 26, 2026
Published: June 16, 2026
Published: May 18, 2026
Published: April 29, 2026
Published: April 29, 2026
Published: April 29, 2026
Published: April 21, 2026
Published: March 26, 2024
Published: March 26, 2024
Published: November 27, 2024
Published: April 13, 2022
Published: November 4, 2024
Published: June 16, 2026
Published: December 5, 2022
Published: August 9, 2022
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.