PT-2026-67975 · WordPress · Contest Gallery
CVE-2026-16055
·
Published
2026-08-05
·
Updated
2026-08-05
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Contest Gallery WordPress plugin versions prior to 30.0.7
Description
The plugin fails to route its front-end login through the standard WordPress authentication flow. Instead, it issues an authentication cookie immediately after the password check. This behavior bypasses installed two-factor authentication and brute-force protection, allowing unlimited and unthrottled password guessing against any account, including administrators, which can lead to full account takeover.
Recommendations
Update Contest Gallery WordPress plugin to version 30.0.7 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contest Gallery