Description
WordPress Plugin Contest Gallery-Photo Contest for WordPress is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently list all users from the blog, disclosing their username and email address. WordPress Plugin Contest Gallery-Photo Contest for WordPress version 13.1.0.6 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 13.1.0.7 or latest
References
https://sploitus.com/exploit?id=WPEX-ID:71EB90F2-BAD2-4DE7-9335-02697AEE9FFE
https://plugins.svn.wordpress.org/contest-gallery/trunk/readme.txt
Related Vulnerabilities
Ruby on Rails Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-8166)
WordPress Plugin Recip.ly 'uploadImage.php' Arbitrary File Upload (1.1.7)
Jboss EAP Improper Restriction of XML External Entity Reference Vulnerability (CVE-2019-10172)
Jenkins Integer Overflow or Wraparound Vulnerability (CVE-2023-36478)
WordPress Plugin Contact Form 7 Captcha Cross-Site Request Forgery (0.0.8)