cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcontest-code-checker contest-code-checker

Direction: descending
Feb 27, 2026

Run Contests, Raffles, and Giveaways with ContestsWP # CVE-2026-25023

CVE, Research URL

CVE-2026-25023

Date
Feb 03, 2026
Research Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in mdedev Run Contests, Raffles, and Giveaways with ContestsWP contest-code-checker allows Retrieve Embedded Sensitive Data.This issue affects Run Contests, Raffles, and Giveaways with ContestsWP: from n/a through <= 2.0.7.
Affected versions
max 2.0.7.
Status
vulnerable
Apr 20, 2025

Run Contests, Raffles, and Giveaways with ContestsWP # CVE-2025-32634

CVE, Research URL

CVE-2025-32634

Date
Apr 17, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mdedev Run Contests, Raffles, and Giveaways with ContestsWP allows Reflected XSS. This issue affects Run Contests, Raffles, and Giveaways with ContestsWP: from n/a through 2.0.6.
Affected versions
max 2.0.6.
Status
vulnerable
Nov 22, 2024

Run Contests, Raffles, and Giveaways with ContestsWP # CVE-2024-11456

CVE, Research URL

CVE-2024-11456

Date
Nov 21, 2024
Research Description
Run Contests, Raffles, and Giveaways with ContestsWP [contest-code-checker] < 2.0.4 CVE-2024-11456 [en] The Run Contests, Raffles, and Giveaways with ContestsWP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 2.0.4.
Status
vulnerable
Nov 16, 2024

Run Contests, Raffles, and Giveaways with ContestsWP # CVE-2022-4974

CVE, Research URL

CVE-2022-4974

Date
Oct 16, 2024
Research Description
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Affected versions
max 1.9.0.
Status
vulnerable
Jun 06, 2024

Run Contests, Raffles, and Giveaways with ContestsWP # 9e275dc25d774b70c248302b422b0d990e837d50

Date
Feb 28, 2022
Research Description
Run Contests, Raffles, and Giveaways with ContestsWP [contest-code-checker] < 1.9.0 WordPress Run Contests, Raffles, and Giveaways with ContestsWP plugin <= 1.7.8 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress Run Contests, Raffles, and Giveaways with ContestsWP plugin (versions <= 1.7.8).
Affected versions
max 1.9.0.
Status
vulnerable