Plugin Vulnerability Hub
Plugin 51 known issues Latest disclosed Mar 23, 2026

Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Vulnerabilities

Review known vulnerability records for the WordPress plugin Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe (`contest-gallery`), including severity, CVE references, affected versions, and patch status.

Known Records
51
High or Critical
28
Linked CVEs
48
Last Updated
Mar 23, 2026
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
51 records include a published patch path.
Severity Mix
5 critical and 23 high severity findings.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: Yes CVE-2026-4021
Contest Gallery <= 28.1.5 - Unauthenticated Privilege Escalation Admin Account Takeover via Registration Confirmation Email-to-ID Type Confusion

The Contest Gallery plugin for WordPress is vulnerable to an authentication bypass leading to admin account takeover in all versions up to, and including, 28.1.5. This is due to the email confirmation handler in `users-registry-check-after-email-or-pin-confirmation.php` using the...

Published
Mar 23, 2026
Patched Release
28.1.6
Affected Versions
Versions up to 28.1.5
Next Step
Update to 28.1.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-24964
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe <= 28.1.2.1 - Authenticated (Subscriber+) Server-Side Request Forgery

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 28.1.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and abov...

Published
Mar 10, 2026
Patched Release
28.1.2.2
Affected Versions
Versions up to 28.1.2.1
Next Step
Update to 28.1.2.2 or newer if supported.
Plugin High Patched: Yes CVE-2026-3180
Contest Gallery <= 28.1.4 - Unauthenticated SQL Injection

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to blind SQL Injection via the ‘cgLostPasswordEmail’ and the ’cgl_mail’ parameter in all versions up to, and including, 28.1.4 due to insufficient escaping on the user...

Published
Mar 02, 2026
Patched Release
28.1.5
Affected Versions
Versions up to 28.1.4
Next Step
Update to 28.1.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-24965
Contest Gallery <= 28.1.1 - Missing Authorization

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 28.1.1. This makes it possible for authenticated attackers,...

Published
Jan 09, 2026
Patched Release
28.1.2
Affected Versions
Versions up to 28.1.1
Next Step
Update to 28.1.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-12849
Contest Gallery <= 28.0.2 - Missing Authorization

The Contest Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 28.0.2. This is due to the plugin registering the `cg_check_wp_admin_upload_v10` AJAX action for both authenticated and unauthenticated users without implementing...

Published
Nov 14, 2025
Patched Release
28.0.3
Affected Versions
Versions up to 28.0.2
Next Step
Update to 28.0.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-62950
Contest Gallery <= 28.0.0 - Cross-Site Request Forgery

The Contest Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 28.0.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized actio...

Published
Oct 12, 2025
Patched Release
28.0.1
Affected Versions
Versions up to 28.0.0
Next Step
Update to 28.0.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-11254
Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.3 - Unauthenticated CSV Injection

The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 27.0.3 via gallery submissions. This makes it possible for unauthenticated attackers to embed untrusted input into exported C...

Published
Oct 10, 2025
Patched Release
28.0.0
Affected Versions
Versions up to 27.0.3
Next Step
Update to 28.0.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-10383
Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.2 - Authenticated (Author+) Stored Cross-Site Scripting

The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple form field parameters in all versions up to, and including, 27.0.2. This is due to insufficient input sanitization and output escaping o...

Published
Oct 03, 2025
Patched Release
27.0.3
Affected Versions
Versions up to 27.0.2
Next Step
Update to 27.0.3 or newer if supported.
Plugin High Patched: Yes CVE-2025-7725
Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI <= 26.1.0 - Unauthenticated Stored Cross-Site Scripting

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment feature in all versions up to, and including...

Published
Jul 31, 2025
Patched Release
26.1.1
Affected Versions
Versions up to 26.1.0
Next Step
Update to 26.1.1 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-48291
Contest Gallery <= 26.0.6 - Reflected Cross-Site Scripting

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 26.0.6 due to insuf...

Published
Jul 11, 2025
Patched Release
26.0.7
Affected Versions
Versions up to 26.0.6
Next Step
Update to 26.0.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-6716
Contest Gallery <= 26.0.8 - Authenticated (Author+) Stored Cross-Site Scripting

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'upload[1][title]' parameter in all versions up to,...

Published
Jul 10, 2025
Patched Release
26.0.9
Affected Versions
Versions up to 26.0.8
Next Step
Update to 26.0.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-3862
Contest Gallery <= 26.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter

Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 26.0.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-l...

Published
May 07, 2025
Patched Release
26.0.7
Affected Versions
Versions up to 26.0.6
Next Step
Update to 26.0.7 or newer if supported.