Vulnerability CVE-2022-36394


Published: 2022-08-23

Description:
Authenticated (author+) SQL Injection (SQLi) vulnerability in Contest Gallery plugin <= 17.0.4 at WordPress.

Type:

CWE-89

(Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'))

 References:
https://patchstack.com/database/vulnerability/contest-gallery/wordpress-contest-gallery-plugin-17-0-4-authenticated-sql-injection-sqli-vulnerability
https://wordpress.org/plugins/contest-gallery/#developers

Copyright 2026, cxsecurity.com

 

Back to Top