S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Feb 23, 2024

CVE-2021-24915 Scanner

CVE-2021-24915 scanner - SQL Injection (SQLi) vulnerability in Contest Gallery plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24915
9.8
CVSS

The Contest Gallery WordPress plugin before 13.1.0.6 does not have capability checks and does not sanitise or escape the cg-search-user-name-original parameter before using it in a SQL statement when exporting users from a gallery, which could allow unauthenticated to perform SQL injections attacks, as well as get the list of all users registered on the blog, including their username and email address

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Contest Gallery – Photo Contest Plugin for WordPress
AFFECTED< 13.1.0.6SAFE ✓≥ 13.1.0.6
Updated Aug 21, 2026View on NVD →
Detail

Vulnerability Overview

CVE-2021-24915 allows attackers to perform SQL injections to access or manipulate the database. This can lead to unauthorized disclosure of all registered users' usernames and email addresses on the affected WordPress site.

Vulnerability Details

The flaw is present in the functionality that handles user exports from galleries. By manipulating the 'cg-search-user-name-original' parameter, attackers can inject arbitrary SQL commands, which are executed by the plugin without proper sanitization or capability checks, leading to potential data breaches.

Possible Effects

Exploiting this vulnerability could lead to:

  • Unauthorized access to sensitive user information.
  • Database manipulation or corruption.
  • Compromise of the entire WordPress site.

Why Choose S4E

S4E provides comprehensive security solutions tailored to your needs. By leveraging our advanced scanning tools and expertise, you benefit from:

  • Real-time vulnerability detection and notifications.
  • Expert guidance on remediation and security best practices.
  • Enhanced protection against emerging threats and vulnerabilities. Join S4E today and fortify your digital assets against sophisticated cyber threats.

References

Solution Advice
  • Update Immediately: Upgrade to Contest Gallery version 13.1.0.6 or later.
  • Review Access Controls: Ensure that only trusted users have administrative privileges.
  • Implement WAF: Use Web Application Firewalls to detect and block SQL injection attempts.
  • Regularly Monitor Logs: Check for suspicious activities indicating exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24915 scanner - SQL Injection (SQLi) vulnerability in Contest Gallery plugin for WordPress | S4E