CVE-2026-3180 is a blind SQL injection vulnerability in the Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress. It affects all versions up to and including 28.1.4. The issue is caused by insufficient escaping of user-controlled input and inadequate preparation of SQL queries involving the 'cgLostPasswordEmail' and 'cgl_mail' parameters. As a result, unauthenticated attackers can inject additional SQL syntax into existing database queries. The vulnerability is blind in nature, meaning exploitation is used to infer database contents indirectly rather than returning query results directly. According to the provided content, the 'cgLostPasswordEmail' parameter was patched in 28.1.4, while the 'cgl_mail' parameter was not fully patched until 28.1.5.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a standalone Python exploit and a Bash helper script for CVE-2026-3180, targeting an unauthenticated blind SQL injection in the WordPress Contest Gallery plugin via the admin-ajax endpoint. Structure is small: README documentation, main exploit script (cve-2026-3180.py), requirements, and sqlmap automation script. The Python script is the primary capability source and presents itself as a feature-rich assessment/exploitation tool with detection, blind extraction, reporting, proxy/Tor support, multithreading, SQLMap/Burp/Nuclei integration, and optional post-exploitation style features such as wp-config extraction and reverse-shell/webshell attempts through SQL file-write primitives. The Bash script wraps sqlmap against the same vulnerable endpoint and parameter to enumerate databases, list tables, and dump wp_users. Based on the available code and documentation, this is a real exploit rather than a detector-only script. It is not tied to a major framework. Main network target is POST /wp-admin/admin-ajax.php with action post_cg1l_resend_unconfirmed_mail_frontend and injectable parameter cgl_mail. The exploit’s overall purpose is to validate and operationalize SQLi against vulnerable WordPress installations, then extract sensitive data and potentially escalate to code execution if backend DB permissions permit file read/write operations.
This repository is not a standalone exploit script but a full PHP code snapshot of the WordPress Contest Gallery plugin, labeled as a PoC for CVE-2026-3180. The codebase is large (100 files) and primarily PHP, with supporting JS snippets, Apache access-control files, and CSV data files. The likely exploit relevance is that it exposes the vulnerable application logic directly, especially through WordPress AJAX handlers and file/ecommerce workflows. Repository structure centers on: (1) frontend and backend AJAX dispatchers (`ajax-functions-frontend.php`, `ajax-functions-backend.php`), (2) gallery shortcode renderers (`cg_gallery*.php`, `cg_galleries.php`, `cg_users_*`), (3) ecommerce/payment modules for PayPal and Stripe, (4) file-management helpers that create, move, replace, and delete files under the WordPress uploads tree, and (5) JSON cache/state generation for gallery entries, comments, and metadata. Main capabilities observed: - Registers many authenticated and unauthenticated WordPress AJAX actions via `wp_ajax_*` and `wp_ajax_nopriv_*`. - Loads gallery data from predictable upload paths under `/contest-gallery/gallery-id-<id>/json/`. - Performs state-changing actions such as rating, cookie setting, ecommerce processing, PDF preview creation, entry activation/deactivation, and gallery/ecommerce file replacement. - Manages downloadable sale files, ZIP creation, invoice generation, CSV key assignment, and order export. - Interacts with external payment APIs (PayPal and Stripe) using hardcoded API base URLs. - Reads/writes many files in the uploads directory, including JSON metadata, invoice PDFs, logs, and ecommerce sale folders. Security-relevant observations: - The attack surface is primarily web/network via WordPress `admin-ajax.php` actions. - Several handlers are exposed to unauthenticated users (`nopriv`) and rely on plugin nonces or surrounding logic for protection. - The plugin performs extensive filesystem operations based on gallery/order context, making file paths and upload directories highly fingerprintable. - There are privileged download/export functions gated by `current_user_can('manage_options')`, but the repository overall contains many sensitive flows that would be attractive exploit targets. - The code includes comments referencing Patchstack and prior fixes, reinforcing that this is a real vulnerable plugin codebase rather than a fake PoC. Overall, this repository appears to serve as a vulnerable target/source snapshot for CVE-2026-3180 analysis. It is best characterized as an operational PoC context: real application code with exploitable surfaces, not merely a detector or README.
This repository is a small proof-of-concept exploit plus a reproducible Docker lab for CVE-2026-3180, an unauthenticated blind SQL injection in the WordPress Contest Gallery plugin 28.1.4 and earlier. The main exploit file, cve-2026-3180.py, is a simple Python script using requests to POST to the WordPress AJAX endpoint /wp-admin/admin-ajax.php with action=post_cg1l_resend_unconfirmed_mail_frontend. It injects SQL syntax into the cgl_mail parameter using an email-shaped payload such as aaaaaaa'OR/**/1=1#@test.com, relying on the plugin's unsafe handling of email input. The script does not automate extraction of database contents; it performs a basic boolean-style test and reports HTTP status and response body length, so it is best classified as a POC rather than a full exploitation tool. Repository structure is straightforward: cve-2026-3180.py is the exploit, dockerfile builds a PHP 8.2 Apache container with MariaDB and WP-CLI, and start.sh provisions a local vulnerable WordPress instance. The startup script creates a MariaDB database and user, downloads WordPress, configures WP_HOME/WP_SITEURL as http://localhost:8080, installs WordPress, installs the contest-gallery plugin pinned to version 28.1.4, and creates a sample post. This makes the repository useful both for demonstrating the vulnerability and for local validation in a controlled environment. Notable capabilities are limited to sending the crafted unauthenticated request and observing a response difference. There is no shell payload, no post-exploitation logic, and no automated blind extraction routine. The most fingerprintable target is the WordPress AJAX endpoint at http://localhost:8080/wp-admin/admin-ajax.php, specifically the action post_cg1l_resend_unconfirmed_mail_frontend. Additional observable environment details include the local WordPress URL, database host 127.0.0.1, and container file paths used to stand up the lab.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.