The Contest Gallery Pro WordPress plugin before 19.1.5 does not escape the wp_user_id GET parameter before concatenating it to an SQL query in management-show-user.php. This may allow malicious users with at administrator privileges (i.e. on multisite WordPress configurations) to leak sensitive information from the site's database.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 14 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-04-14T14:18:40.271Z

Reserved: 2022-11-28T15:01:33.860Z

Link: CVE-2022-4154

cve-icon Vulnrichment

Updated: 2024-08-03T01:27:54.540Z

cve-icon NVD

Status : Modified

Published: 2022-12-26T13:15:12.837

Modified: 2025-04-14T15:15:22.547

Link: CVE-2022-4154

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.