CVE-2022-4157 is an SQL Injection vulnerability affecting the Contest Gallery and Contest Gallery Pro WordPress plugins prior to version 19.1.5.1. The vulnerability stems from improper sanitization of the cg_option_id POST parameter, allowing authenticated attackers with administrator privileges to inject malicious SQL queries. This could lead to the leakage of sensitive information from the site's database. Rated with a CVSS score of 4.9 (Medium), the vulnerability requires high privileges (administrator) and has a low attack complexity, but does not impact integrity or availability. Its primary impact is on confidentiality. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. The CVE has also received minimal community discussion and media coverage, indicating a low level of public awareness or concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 19.1.5.1CPE matchmatch criteria | cpe:2.3:a:contest-gallery:contest_gallery:*:*:*:*:*:wordpress:*:* | ||
< 19.1.5.1CPE matchmatch criteria | cpe:2.3:a:contest-gallery:contest_gallery:*:*:*:*:pro:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.