Pricing
Solutions
WordPress security
Instantly fix and mitigate vulnerabilities
Plugin auditing
Paid auditing for WordPress vendors
Managed VDP
Start a security program for your plugins
Bug Bounty
Join the community and earn bounties
Enterprise API
At scale monitoring and vPatching for hosts
Vulnerability database
The latest WordPress security intelligence
Login
Start trial
Contest Gallery
Wasiliy Strecker / ContestGallery developer
Developer
28.0.6
Latest version
1,000
Installations
2 days ago
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
29 fixed
15 Mitigation rules
Missing Authorization vulnerability
<= 28.0.2
6 days ago
Cross Site Request Forgery (CSRF) vulnerability
<= 28.0.0
Oct 12, 2025
Unauthenticated CSV Injection vulnerability
<= 27.0.3
Oct 10, 2025
Authenticated (Author+) Stored Cross-Site Scripting vulnerability
<= 27.0.2
Oct 3, 2025
Unauthenticated Stored Cross-Site Scripting vulnerability
<= 26.1.0
Jul 31, 2025
Cross Site Scripting (XSS) Vulnerability
<= 26.0.6
Jul 11, 2025
Authenticated (Author+) Stored Cross-Site Scripting vulnerability
<= 26.0.8
Jul 10, 2025
Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter vulnerability
<= 26.0.6
May 8, 2025
Unauthenticated Stored Cross-Site Scripting vulnerability
<= 26.0.0.1
Feb 27, 2025
SQL Injection vulnerability
<= 25.1.0
Jan 31, 2025
Cross Site Scripting (XSS) vulnerability
<= 24.0.3
Dec 30, 2024
Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover vulnerability
<= 24.0.7
Nov 27, 2024
Unauthenticated SQL Injection vulnerability
<= 24.0.3
Nov 4, 2024
Unauthenticated Comment UserID And IP address Disclosure vulnerability
<= 23.1.2
Aug 16, 2024
Cross Site Scripting (XSS) vulnerability
<= 23.1.2
Jul 24, 2024
Arbitrary File Deletion vulnerability
<= 21.3.4
Apr 22, 2024
Reflected Cross Site Scripting (XSS) vulnerability
<= 24.0.3
Mar 28, 2024
SQL Injection vulnerability
<= 21.3.2
Mar 26, 2024
SQL Injection vulnerability
<= 21.3.4
Mar 26, 2024
Author+ Stored Cross Site Scripting vulnerability
< 21.3.1
Mar 12, 2024
CSRF Leading to Gallery Creation vulnerability
<= 21.2.8.4
Feb 5, 2024
Unauth. Stored XSS via HTTP Headers vulnerability
< 21.2.8.1
Oct 31, 2023
Cross Site Scripting (XSS) vulnerability
<= 21.1.2
Mar 27, 2023
Unauth. Stored Cross-Site Scripting (XSS) vulnerability
<= 13.1.0.9
Nov 23, 2022
Authenticated SQL Injection (SQLi) vulnerability
<= 17.0.4
Aug 9, 2022
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 13.1.0.9
Dec 20, 2021
Missing Access Controls to Unauthenticated SQL injection (SQLi) / Email Address Disclosure vulnerability
<= 13.1.0.5
Nov 1, 2021
Email Address Disclosure vulnerability
<= 13.1.0.6
Nov 1, 2021
Cross-Site Request Forgery (CSRF) vulnerability
<= 10.4.4
Jul 10, 2019