Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-51524 | The Contest Gallery WordPress plugin before 19.1.5.1, Contest Gallery Pro WordPress plugin before 19.1.5.1 do not escape the cg_deactivate and cg_activate POST parameters before concatenating it to an SQL query in 2_deactivate.php and 4_activate.php, respectively. This may allow malicious users with at least author privilege to leak sensitive information from the site's database. |
Mon, 14 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-04-14T14:19:31.814Z
Reserved: 2022-11-28T15:03:43.122Z
Link: CVE-2022-4163
Updated: 2024-08-03T01:34:48.814Z
Status : Modified
Published: 2022-12-26T13:15:13.403
Modified: 2025-04-14T15:15:23.080
Link: CVE-2022-4163
No data.
OpenCVE Enrichment
No data.
No weakness.
EUVD