Executive brief
The Contest Gallery plugin for WordPress, which is used to manage and display photo or video contests, contains a critical security flaw. An unauthorized attacker can use this vulnerability to access and steal sensitive information from your website's database. This could lead to the exposure of user data or administrative credentials, potentially resulting in a full site takeover.
Technical details
A SQL injection vulnerability exists in the Contest Gallery plugin for WordPress due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw allows an unauthenticated remote attacker to send specially crafted requests to the server to execute arbitrary SQL queries. This can be leveraged to extract sensitive data from the database, such as user hashes or configuration details. The vulnerability is present in versions 28.1.6 and earlier and has been addressed in version 28.1.7.
Affected products
- Wasiliy Strecker Contest Gallery <= 28.1.6
Timeline
- 2026-03-09: other: Vulnerability reported by Trương Hữu Phúc
- 2026-04-21: advisory: Patchstack published advisory and mitigation rules
- 2026-06-15: disclosed: CVE published to NVD