The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_deactivate and cg_activate POST parameters before concatenating it to an SQL query in 2_deactivate.php and 4_activate.php, respectively. This may allow malicious users with at least author privilege to leak sensitive information from the site’s database.
[
{
"vendor": "Unknown",
"product": "Contest Gallery",
"versions": [
{
"status": "affected",
"versionType": "custom",
"version": "0",
"lessThan": "19.1.5.1"
}
],
"defaultStatus": "unaffected",
"collectionURL": "https://wordpress.org/plugins"
},
{
"vendor": "Unknown",
"product": "Contest Gallery Pro",
"versions": [
{
"status": "affected",
"versionType": "custom",
"version": "0",
"lessThan": "19.1.5.1"
}
],
"defaultStatus": "unaffected"
}
]