PT-2026-67090 · WordPress · Contest Gallery

CVE-2026-16057

·

Published

2026-08-03

·

Updated

2026-08-04

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Contest Gallery WordPress plugin versions prior to 30.0.7
Description Insufficient per-object capability and nonce checks in a post-deletion handler allow users with Author-level permissions or higher to permanently delete arbitrary posts, pages, and other content that they do not own. The system relies solely on a coarse role-membership test, which is inadequate for verifying if a user has the specific right to delete a particular object.
Recommendations Update The Contest Gallery WordPress plugin to version 30.0.7 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16057

Affected Products

Contest Gallery