CVE-2022-4164 | Contest Gallery Plugin/Contest Gallery Pro Plugin 19.1.5 on WordPress POST Parameter 0_change-gallery.php cg_multiple_files_for_post sql injection
A vulnerability, which was classified as critical, has been found in Contest Gallery Plugin and Contest Gallery Pro Plugin 19.1.5 on WordPress. Affected by this issue is some unknown functionality of the file 0_change-gallery.php of the component POST Parameter Handler. The manipulation of the argument cg_multiple_files_for_post leads to sql injection.
This vulnerability is handled as CVE-2022-4164. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.