Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 60 vulnerability records associated with Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe, published between 2019 and 2026.

Dataset last synchronized: 2026-08-02 09:41:47 UTC

At a glance

Security Snapshot

60Total records
5Critical
27High
28Medium
0Low
0Informational
60Patched records
0Currently marked unpatched
2019-06-12First disclosure
2026-07-27Latest disclosure
57 of 60CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
201911 records
202122 records
20222020 records
202322 records
20241212 records
20251010 records
20261313 records

Severity Breakdown

SeverityRecordsShare
Critical58.3%
High2745%
Medium2846.7%

Vulnerability-Type Breakdown

SQL Injection

26 records43.3%

First: 2022. Latest: 2026.

Cross-Site Scripting

17 records28.3%

First: 2021. Latest: 2026.

Missing Authorization

5 records8.3%

First: 2024. Latest: 2026.

CSRF

4 records6.7%

First: 2019. Latest: 2025.

Information Disclosure

3 records5%

First: 2021. Latest: 2026.

Privilege Escalation

2 records3.3%

First: 2024. Latest: 2026.

Other

2 records3.3%

First: 2025. Latest: 2026.

Authentication Bypass

1 record1.7%

First: 2026. Latest: 2026.

Patch Status

Patched
60
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 30.0.7
  • 30.0.1
  • 30.0.3
  • 28.1.7
  • 29.0.0
  • 28.1.6
  • 28.1.3
  • 28.1.2.2
  • 28.1.5
  • 28.1.2
  • 28.0.3
  • 28.0.1
  • 28.0.0
  • 27.0.3
  • 26.1.1
  • 26.0.7
  • 26.0.9
  • 26.0.1
  • 25.1.2
  • 24.0.4
  • 24.0.8
  • 23.1.3
  • 21.3.6
  • 21.3.5
  • 21.3.2.1
  • 21.3.1
  • 21.2.9
  • 21.2.8.1
  • 21.1.2.1
  • 19.1.5.1
  • 19.1.5
  • 17.0.5
  • 13.1.0.6
  • 14.0.0
  • 13.1.0.7
  • 10.4.5

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-19.1.4.1Contest Gallery <= 19.1.4.1 - Unauthenticated SQL Injection via cg_FieldsDecember 5, 202219.1.5High
*-19.1.4.1Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via cg_activate and cg_deactivateNovember 29, 202219.1.5High
*-19.1.4.1Contest Gallery <= 19.1.4.1 - Authenticated (Author+) SQL Injection via option_idNovember 29, 202219.1.5High
*-13.1.0.9Contest Gallery <= 13.1.0.9 - Cross-Site ScriptingNovember 23, 202214.0.0Medium
*-17.0.4Contest Gallery <= 17.0.4 - Authenticated (Author+) SQL InjectionAugust 9, 202217.0.5High
*-17.0.4Contest Gallery – Files Upload and Contest Plugin for WordPress <= 17.0.4 - Admin+ SQL InjectionJune 1, 202217.0.5High
*-13.1.0.5Contest Gallery – Photo Contest Plugin for WordPress <= 13.1.0.5 - SQL InjectionApril 13, 202213.1.0.6Critical
*-13.1.0.9Contest Gallery <= 13.1.0.9 - Authenticated (Author+) Stored Cross-Site ScriptingDecember 20, 202114.0.0Medium
[*, 13.1.0.7)Contest Gallery < 13.1.0.7 - Authenticated Email Address DisclosureNovember 1, 202113.1.0.7Medium
*-10.4.4Contest Gallery – Photo Contest Plugin for WordPress <= 10.4.4 - Cross-Site Request ForgeryJune 12, 201910.4.5High

Selected source records

Latest Records

HighCVE-2026-65447

Contest Gallery <= 30.0.6 - Unauthenticated Stored Cross-Site Scripting

Published: July 27, 2026

Affected versions
*-30.0.6
Patched versions
30.0.7
Original Wordfence record
MediumCVE-2026-57662

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 30.0.0 - Authenticated (Contributor+) SQL Injection

Published: June 26, 2026

Affected versions
*-30.0.0
Patched versions
30.0.1
Original Wordfence record
HighCVE-2026-12165

Contest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' Parameter

Published: June 16, 2026

Affected versions
*-30.0.2
Patched versions
30.0.3
Original Wordfence record
HighCVE-2026-8912

Contest Gallery <= 28.1.6 - Unauthenticated SQL Injection

Published: May 18, 2026

Affected versions
*-28.1.6
Patched versions
28.1.7
Original Wordfence record
MediumCVE-2026-42657

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.7 - Missing Authorization

Published: April 29, 2026

Affected versions
*-28.1.7
Patched versions
29.0.0
Original Wordfence record
MediumCVE-2026-42656

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting

Published: April 29, 2026

Affected versions
*-28.1.6
Patched versions
29.0.0
Original Wordfence record
MediumCVE-2026-42660

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.7 - Authenticated (Subscriber+) Sensitive Information Exposure

Published: April 29, 2026

Affected versions
*-28.1.7
Patched versions
29.0.0
Original Wordfence record
HighCVE-2026-40771

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.6 - Unauthenticated SQL Injection

Published: April 21, 2026

Affected versions
*-28.1.6
Patched versions
28.1.7
Original Wordfence record

Highest-Severity Records

CriticalCVE-2024-30238

Photos and Files Contest Gallery <= 21.3.2 - Authenticated (Contributor+) SQL Injection

Published: March 26, 2024

Affected versions
*-21.3.2
Patched versions
21.3.2.1
Original Wordfence record
CriticalCVE-2024-30236

Photos and Files Contest Gallery <= 21.3.4 - Authenticated (Contributor+) SQL Injection

Published: March 26, 2024

Affected versions
*-21.3.4
Patched versions
21.3.5
Original Wordfence record
CriticalCVE-2024-11103

Contest Gallery <= 24.0.7 - Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover

Published: November 27, 2024

Affected versions
*-24.0.7
Patched versions
24.0.8
Original Wordfence record
CriticalCVE-2021-24915

Contest Gallery – Photo Contest Plugin for WordPress <= 13.1.0.5 - SQL Injection

Published: April 13, 2022

Affected versions
*-13.1.0.5
Patched versions
13.1.0.6
Original Wordfence record
CriticalCVE-2024-10687

Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons <= 24.0.3 - Unauthenticated SQL Injection

Published: November 4, 2024

Affected versions
*-24.0.3
Patched versions
24.0.4
Original Wordfence record
HighCVE-2026-12165

Contest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' Parameter

Published: June 16, 2026

Affected versions
*-30.0.2
Patched versions
30.0.3
Original Wordfence record
HighCVE-2022-4150

Contest Gallery (Pro) <= 19.1.5 - SQL Injection via option_id

Published: December 5, 2022

Affected versions
*-19.1.5
Patched versions
19.1.5.1
Affected versions
*-19.1.5
Patched versions
19.1.5.1
Original Wordfence record
HighCVE-2022-36394

Contest Gallery <= 17.0.4 - Authenticated (Author+) SQL Injection

Published: August 9, 2022

Affected versions
*-17.0.4
Patched versions
17.0.5
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory