CVE-2026-40771CRITICAL NVDCVSS Score 9.3Severity CRITICALPublished Jun 15, 2026Vendor unknownDescriptionUnauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions.Referenceshttps://patchstack.com/database/wordpress/plugin/contest-gallery/vulnerability/wordpress-contest-gallery-plugin-28-1-6-sql-injection-vulnerability?_s_id=cve