CVE-2026-3180Disclosure

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to blind SQL Injection via the ‘cgLostPasswordEmail’ and the ’cgl_mail’ parameter in all versions up to, and including, 28.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerability's ’cgLostPasswordEmail’ parameter was patched in version 28.1.4, and the ’cgl_mail’ parameter was patched in version 28.1.5.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 3 mentions (2026-03-02); latest day: 2
  • 9 total mentions across 6 days

Deep dive

Activity timeline9 mentions / 6d
01223Mentions · 2026-03-02: 3Mentions · 2026-03-03: 1Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-30: 1Mentions · 2026-07-12: 2PoC Mentioned / Linked · 2026-07-12: 1Patch / Workaround · 2026-03-03: 1Technical Details · 2026-03-02: 3Technical Details · 2026-03-03: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-07-12: 203-0203-0303-0503-0603-3007-12
Signal classification3 categories
Disclosure
666.7%
General
222.2%
Patch
111.1%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-023
Disclosure3
2026-03-031
Patch1
2026-03-051
Disclosure1
2026-03-061
General1
2026-03-301
General1
2026-07-122
Disclosure2
Full discourse9 posts
  • Mr. Link@MrLinkEc
    Patch

    🚨 ¿Tu web está en WordPress? ALERTA DE CIBERSEGURIDAD Se publicó CVE-2026-3180 (CVSS 7.5): Blind SQL Injection en el plugin Contest Gallery para WordPress. ⚠️ Explotable sin autenticación a través de cgLostPasswordEmail y cgl_mail (CWE-89). 🎯 Permite extraer usuarios, hashes, correos y datos sensibles de la base de datos. 📌 Afecta versiones 28.1.4 o inferiores. ✅ Mitigación: actualizar a 28.1.5 o superior. La mayoría de brechas en WordPress no atacan el core, atacan plugins vulnerables. #NoSeDejenHackear 😎

    Post summary

    CVE-2026-3180 is a blind SQL injection in the Contest Gallery WordPress plugin affecting versions 28.1.4 and below, with mitigation via updating to 28.1.5 or newer.

    1411031.2K
    55.8K followersView on X
  • Un9nPlayer@Un9nPlayer
    Disclosure

    CVE-2026-3180: WordPress Contest Gallery Blind SQL Injection in Unauthenticated AJAX Flow https://www.agniops.in/blog/cve-2026-3180-wordpress-contest-gallery-blind-sqli

    Post summary

    The post announces CVE-2026-3180, a Blind SQL Injection flaw affecting the WordPress Contest Gallery plugin via an unauthenticated AJAX endpoint.

    00001236
    1.3K followersView on X
  • AgniOpsIn@AgniOpsIn
    Disclosure

    CVE-2026-3180: WordPress Contest Gallery Blind SQL Injection in Unauthenticated AJAX Flow https://www.agniops.in/blog/cve-2026-3180-wordpress-contest-gallery-blind-sqli

    Post summary

    CVE-2026-3180 reveals a blind SQL injection flaw in the WordPress Contest Gallery plugin’s unauthenticated AJAX flow, with an online blog post providing details.

    00000163
    6 followersView on X
  • David@DavidMarquet19
    General

    📌 Top CVEs recientes (CVSS>=7.0): 1. ⚠️ CVE-2025-48605 (CVSS: 8.4) 2. ⚠️ CVE-2025-48602 (CVSS: 8.4) 3. ⚠️ CVE-2025-48582 (CVSS: 8.4) 4. 💉 CVE-2026-3180 (CVSS: 7.5) 5. 🔥 CVE-2026-3132 (CVSS: 8.8) #CyberSecurity #CVE #Infosec

    Post summary

    The post simply enumerates recent high‑CVSS CVEs without offering additional technical details, mitigation steps, or exploit information.

    00000183
    162 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-3180 (CVSS:7.5, HIGH) is Awaiting Analysis. The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to blind..https://nvd.nist.gov/vuln/detail/CVE-2026-3180 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-3180 is a high‑severity vulnerability affecting the Contest Gallery WordPress plugin, and it is currently awaiting analysis.

    0000044
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3180 (CVSS:7.5, HIGH) is Awaiting Analysis. The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to blind..https://nvd.nist.gov/vuln/detail/CVE-2026-3180 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-3180 is reported with a CVSS score of 7.5 (HIGH) for the Contest Gallery WordPress plugin, currently awaiting analysis. No PoC, exploit code, patch, or evidence of active exploitation is provided.

    0000039
    173 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3180 Blind SQL Injection in Contest Gallery WordPress Plugin vi... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3180 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post announces a blind SQL injection vulnerability (CVE-2026-3180) in the Contest Gallery WordPress plugin, linking to a vulnerability detail page but providing no PoC, exploit, or patch information.

    0000056
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3180 The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to blind SQL Injection via the ‘cgLostPasswordEmail’ and… https://www.cve.org/CVERecord?id=CVE-2026-3180 ----- Traducción: CVE-2026-3180 The… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-3180, a blind SQL injection vulnerability in the Contest Gallery WordPress plugin, but provides no PoC, exploit, or mitigation details.

    0000037
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3180 The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to blind SQL Injection via the ‘cgLostPasswordEmail’ and… https://www.cve.org/CVERecord?id=CVE-2026-3180

    Post summary

    The Contest Gallery WordPress plugin is vulnerable to blind SQL injection via the cgLostPasswordEmail parameter, as identified by CVE-2026-3180.

    00000224
    56.6K followersView on X

Explore more