CVE-2022-4150 | Contest Gallery Plugin/Contest Gallery Pro Plugin 19.1.5 on WordPress POST Parameter order-custom-fields-with-and-without-search.php option_id sql injection
A vulnerability was found in Contest Gallery Plugin and Contest Gallery Pro Plugin 19.1.5 on WordPress. It has been classified as critical. Affected is an unknown function of the file order-custom-fields-with-and-without-search.php of the component POST Parameter Handler. The manipulation of the argument option_id leads to sql injection.
This vulnerability is traded as CVE-2022-4150. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.