
PEACH
Uma estrutura de isolamento de inquilino
CVE-2026-16586 is a Second-Order SQL Injection vulnerability in the Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress. It affects all versions up to and including 30.0.7, allowing authenticated attackers with author-level access or above to extract sensitive information from the database. The vulnerability was published on August 15, 2026, and assigned by Wordfence. It carries a CVSS v3.1 base score of 6.5 (Medium/High) (Wordfence, ENISA EUVD).
The root cause is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). The vulnerability is a second-order SQL injection, meaning malicious input is first stored in the database via the cg_multiple_files_for_post parameter and later retrieved and used unsafely in a subsequent SQL query through the cgRealId field, due to insufficient escaping and lack of prepared statements. The vulnerable code paths are present in ajax/ajax-functions-backend.php (lines 135, 286, 310) and v10/v10-admin/gallery/change-gallery/0_change-gallery.php (lines 475, 683) in versions 30.0.6 and 30.0.7. Exploitation requires network access and at least author-level WordPress authentication (Wordfence, WordPress Trac).
Successful exploitation allows authenticated attackers to append additional SQL queries to existing database queries, enabling extraction of sensitive information from the WordPress database — including user credentials, email addresses, private post content, and plugin configuration data. The impact is primarily a high confidentiality loss with no direct integrity or availability impact per the CVSS scoring. Lateral movement within the WordPress environment is possible if extracted credentials are reused or if administrative account data is recovered (Wordfence, ENISA EUVD).
As of the disclosure date, there is no known public exploit code and no evidence of in-the-wild exploitation. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, reflecting the requirement for authenticated access. The EPSS score is approximately 0.33%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Wordfence, ENISA EUVD).
cg_multiple_files_for_post parameter during a file upload or post creation action. This payload is stored in the database without proper sanitization.cgRealId value and incorporate it into a new SQL query without adequate escaping or prepared statements.cg_multiple_files_for_post or cgRealId; database error logs indicating malformed SQL queries or unexpected UNION/SELECT statements.wp_users table following suspicious activity.Users should update the Contest Gallery plugin to a version above 30.0.7 as soon as a patched release is available. The fix was introduced via the changeset at the WordPress plugin repository. Until an update is applied, site administrators should restrict author-level account creation and monitor database activity for anomalous queries. Web application firewalls (WAFs) with SQL injection rules can provide partial mitigation (Wordfence, WordPress Changeset).
Wordfence disclosed the vulnerability as part of their weekly WordPress vulnerability report for August 10–16, 2026, and published the advisory through their threat intelligence platform. No significant broader media coverage or notable researcher commentary beyond the Wordfence disclosure has been identified (Wordfence Blog).
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."