The Contest Gallery WordPress plugin before 19.1.5, Contest Gallery Pro WordPress plugin before 19.1.5 do not escape the option_id POST parameter before concatenating it to an SQL query in edit-options.php. This may allow malicious users with at least author privilege to leak sensitive information from the site’s database.
[
{
"vendor": "Unknown",
"product": "Contest Gallery",
"versions": [
{
"status": "affected",
"versionType": "custom",
"version": "0",
"lessThan": "19.1.5"
}
],
"defaultStatus": "unaffected",
"collectionURL": "https://wordpress.org/plugins"
},
{
"vendor": "Unknown",
"product": "Contest Gallery Pro",
"versions": [
{
"status": "affected",
"versionType": "custom",
"version": "0",
"lessThan": "19.1.5"
}
],
"defaultStatus": "unaffected"
}
]