WordPress Run Contests, Raffles, and Giveaways with ContestsWP Sensitive Data Exposure Vulnerability

Vulnerability

A vulnerability allowing the exposure of sensitive system information to an unauthorized control sphere has been identified in the WordPress plugin 'Run Contests, Raffles, and Giveaways with ContestsWP', specifically in versions through 2.0.7. This issue arises from the contest-code-checker component of the plugin, which improperly handles embedded sensitive data, potentially allowing unauthorized users to retrieve this information.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information embedded within the affected plugin, which could then be used to exploit other weaknesses in the system.

Remediation

Users of the 'Run Contests, Raffles, and Giveaways with ContestsWP' WordPress plugin should update to version 2.1.1 or later to address this vulnerability. Patchstack users can enable auto-update for vulnerable plugins.

Added: Feb 3, 2026, 3:57 PM
Updated: Feb 3, 2026, 5:38 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
2.5
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.