PT-2026-22660 · WordPress · Contest Gallery – Upload & Vote Photos

Thomas Sanzey

·

Published

2026-03-02

·

Updated

2026-03-30

·

CVE-2026-3180

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress versions through 28.1.4
Description The software is susceptible to a blind SQL Injection issue due to inadequate escaping of user-supplied parameters and insufficient preparation of existing SQL queries. This allows unauthenticated attackers to inject additional SQL queries into existing ones, potentially extracting sensitive information from the database. The issue affects the cgLostPasswordEmail and cgl mail parameters. The cgLostPasswordEmail parameter was addressed in version 28.1.4, and the cgl mail parameter was addressed in version 28.1.5.
Recommendations Versions prior to 28.1.5 should be updated. As a temporary workaround, restrict access to the parameters cgLostPasswordEmail and cgl mail.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3180

Affected Products

Contest Gallery – Upload & Vote Photos