PT-2026-67090 · WordPress · Contest Gallery
CVE-2026-16057
·
Published
2026-08-03
·
Updated
2026-08-04
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Contest Gallery WordPress plugin versions prior to 30.0.7
Description
Insufficient per-object capability and nonce checks in a post-deletion handler allow users with Author-level permissions or higher to permanently delete arbitrary posts, pages, and other content that they do not own. The system relies solely on a coarse role-membership test, which is inadequate for verifying if a user has the specific right to delete a particular object.
Recommendations
Update The Contest Gallery WordPress plugin to version 30.0.7 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contest Gallery