Executive brief
Contest Gallery is a WordPress plugin used to manage and display photo or video contests. A security flaw allows users with 'Contributor' level access to perform unauthorized database queries. This could lead to the theft of sensitive information from the website's database or disruption of site operations.
Technical details
A SQL injection vulnerability exists in the Contest Gallery plugin for WordPress (versions up to 30.0.0) due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is exploitable by an attacker with Contributor-level privileges. By sending specially crafted network requests, an attacker can bypass intended query logic to interact directly with the underlying database. This can result in unauthorized data exfiltration or limited service disruption. The issue is addressed in version 30.0.1.
Affected products
- Wasiliy Strecker Contest Gallery <= 30.0.0
Timeline
- 2026-05-08: other: Reported by researcher Trương Hữu Phúc
- 2026-06-26: advisory: Published by Patchstack and NVD
- 2026-06-26: patched: Fixed in version 30.0.1