SQL Injection
26 records43.3%First: 2022. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 60 vulnerability records associated with Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe, published between 2019 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2019 | 1 | |
| 2021 | 2 | |
| 2022 | 20 | |
| 2023 | 2 | |
| 2024 | 12 | |
| 2025 | 10 | |
| 2026 | 13 |
| Severity | Records | Share |
|---|---|---|
| Critical | 5 | 8.3% |
| High | 27 | 45% |
| Medium | 28 | 46.7% |
First: 2022. Latest: 2026.
First: 2021. Latest: 2026.
First: 2024. Latest: 2026.
First: 2019. Latest: 2025.
First: 2021. Latest: 2026.
First: 2024. Latest: 2026.
First: 2025. Latest: 2026.
First: 2026. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
30.0.730.0.130.0.328.1.729.0.028.1.628.1.328.1.2.228.1.528.1.228.0.328.0.128.0.027.0.326.1.126.0.726.0.926.0.125.1.224.0.424.0.823.1.321.3.621.3.521.3.2.121.3.121.2.921.2.8.121.1.2.119.1.5.119.1.517.0.513.1.0.614.0.013.1.0.710.4.5Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-19.1.4.1 | Contest Gallery <= 19.1.4.1 - Unauthenticated SQL Injection via cg_Fields | December 5, 2022 | 19.1.5 | High |
*-19.1.4.1 | Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_activate and cg_deactivate | November 29, 2022 | 19.1.5 | High |
*-19.1.4.1 | Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via option_id | November 29, 2022 | 19.1.5 | High |
*-13.1.0.9 | Contest Gallery <= 13.1.0.9 - Cross-Site Scripting | November 23, 2022 | 14.0.0 | Medium |
*-17.0.4 | Contest Gallery <= 17.0.4 - Authenticated (Author+) SQL Injection | August 9, 2022 | 17.0.5 | High |
*-17.0.4 | Contest Gallery – Files Upload and Contest Plugin for WordPress <= 17.0.4 - Admin+ SQL Injection | June 1, 2022 | 17.0.5 | High |
*-13.1.0.5 | Contest Gallery – Photo Contest Plugin for WordPress <= 13.1.0.5 - SQL Injection | April 13, 2022 | 13.1.0.6 | Critical |
*-13.1.0.9 | Contest Gallery <= 13.1.0.9 - Authenticated (Author+) Stored Cross-Site Scripting | December 20, 2021 | 14.0.0 | Medium |
[*, 13.1.0.7) | Contest Gallery < 13.1.0.7 - Authenticated Email Address Disclosure | November 1, 2021 | 13.1.0.7 | Medium |
*-10.4.4 | Contest Gallery – Photo Contest Plugin for WordPress <= 10.4.4 - Cross-Site Request Forgery | June 12, 2019 | 10.4.5 | High |
Selected source records
Published: July 27, 2026
Published: June 26, 2026
Published: June 16, 2026
Published: May 18, 2026
Published: April 29, 2026
Published: April 29, 2026
Published: April 29, 2026
Published: April 21, 2026
Published: March 26, 2024
Published: March 26, 2024
Published: November 27, 2024
Published: April 13, 2022
Published: November 4, 2024
Published: June 16, 2026
Published: December 5, 2022
Published: August 9, 2022
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.