Subscriber Cross Site Scripting (XSS) in Contest Gallery <= 28.1.6 versions.
Update the WordPress Contest Gallery Plugin to the latest available version (at least 29.0.0).