Input validation vulnerability in Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting Competition Plugin for WordPress 21.3.0

The Photos and Files Contest Gallery is a plugin for WordPress that allows users to upload photos and files, share them on social media, and participate in voting competitions. However, this plugin is currently at risk for a type of cyber attack called Stored Cross-Site Scripting. This is because the plugin does not properly clean up the information entered by users, making it possible for attackers with certain levels of access to insert harmful web scripts that can run when a user visits a certain page.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.