Vulnerabilities and security researches forcontest-code-checker contest-code-checker
Direction: ascendingJun 06, 2024
Run Contests, Raffles, and Giveaways with ContestsWP # 9e275dc25d774b70c248302b422b0d990e837d50
- CVE, Research URL
- Date
- Feb 28, 2022
- Research Description
- Run Contests, Raffles, and Giveaways with ContestsWP [contest-code-checker] < 1.9.0 WordPress Run Contests, Raffles, and Giveaways with ContestsWP plugin <= 1.7.8 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Run Contests, Raffles, and Giveaways with ContestsWP plugin (versions <= 1.7.8).
- Affected versions
-
max 1.9.0.
- Status
-
vulnerable
Nov 16, 2024
Run Contests, Raffles, and Giveaways with ContestsWP # CVE-2022-4974
- CVE, Research URL
- Date
- Oct 16, 2024
- Research Description
- The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
- Affected versions
-
max 1.9.0.
- Status
-
vulnerable
Nov 22, 2024
Run Contests, Raffles, and Giveaways with ContestsWP # CVE-2024-11456
- CVE, Research URL
- Date
- Nov 21, 2024
- Research Description
- Run Contests, Raffles, and Giveaways with ContestsWP [contest-code-checker] < 2.0.4 CVE-2024-11456 [en] The Run Contests, Raffles, and Giveaways with ContestsWP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
max 2.0.4.
- Status
-
vulnerable
Apr 20, 2025
Run Contests, Raffles, and Giveaways with ContestsWP # CVE-2025-32634
- CVE, Research URL
- Date
- Apr 17, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mdedev Run Contests, Raffles, and Giveaways with ContestsWP allows Reflected XSS. This issue affects Run Contests, Raffles, and Giveaways with ContestsWP: from n/a through 2.0.6.
- Affected versions
-
max 2.0.6.
- Status
-
vulnerable
Feb 27, 2026
Run Contests, Raffles, and Giveaways with ContestsWP # CVE-2026-25023
- CVE, Research URL
- Date
- Feb 03, 2026
- Research Description
- Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in mdedev Run Contests, Raffles, and Giveaways with ContestsWP contest-code-checker allows Retrieve Embedded Sensitive Data.This issue affects Run Contests, Raffles, and Giveaways with ContestsWP: from n/a through <= 2.0.7.
- Affected versions
-
max 2.0.7.
- Status
-
vulnerable