Record summary

CVE-2021-24915 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 10, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

Contest Gallery – Photo Contest Plugin for WordPress

CVE List13.1.0.6 to < 13.1.0.6affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALContest Gallery < 13.1.0.6 - SQL injectionCVSS 9.8

The plugin does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address.

Impact

Unauthenticated attackers can exploit SQL injection to extract database contents and enumerate all registered users including their email addresses, potentially facilitating targeted phishing attacks.

Remediation

Fixed in version 13.1.0.6

WeaknessesCWE-89
Authorsr3Y3r53
Template tagscve2021cvewordpresswp-pluginwpscanwpcontest-gallerycontest_gallerysqlivulnvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:contest_gallery:contest_gallery:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/contest-gallery/
FOFA: body=/wp-content/plugins/contest-gallery/

Source: ProjectDiscovery

References

3