PT-2026-22660 · WordPress · Contest Gallery – Upload & Vote Photos
Thomas Sanzey
·
Published
2026-03-02
·
Updated
2026-03-30
·
CVE-2026-3180
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress versions through 28.1.4
Description
The software is susceptible to a blind SQL Injection issue due to inadequate escaping of user-supplied parameters and insufficient preparation of existing SQL queries. This allows unauthenticated attackers to inject additional SQL queries into existing ones, potentially extracting sensitive information from the database. The issue affects the
cgLostPasswordEmail and cgl mail parameters. The cgLostPasswordEmail parameter was addressed in version 28.1.4, and the cgl mail parameter was addressed in version 28.1.5.Recommendations
Versions prior to 28.1.5 should be updated. As a temporary workaround, restrict access to the parameters
cgLostPasswordEmail and cgl mail.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contest Gallery – Upload & Vote Photos