Impact
The Contest Gallery WordPress plugin contains a second‑order SQL injection flaw that originates in the handling of the 'cg_multiple_files_for_post' parameter, which is later used as 'cgRealId' in an existing query without sufficient escaping. An attacker who is authenticated with an Author or higher role can construct a payload that is injected into the database query when the multiple file operation is executed, allowing the retrieval of arbitrary data from the database. This vulnerability is an instance of CWE‑89 and can compromise the confidentiality of all application data stored in the WordPress database.
Affected Systems
All installations of the Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe WordPress plugin through version 30.0.7 (inclusive) are affected. Users running any of these releases are at risk if they have enabled the Multiple Files feature and have authors or higher roles.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate to high risk, and the vulnerability requires authentication with author-level privileges, limiting the attack surface to users who have been granted publishing capability. The EPSS score is currently not available, and the flaw is not listed in the CISA KEV catalog, suggesting that there have not been widely reported public exploitation events yet. Nevertheless, because the flaw can be leveraged to exfiltrate data, it warrants prompt remediation.
OpenCVE Enrichment