PT-2026-67975 · WordPress · Contest Gallery

CVE-2026-16055

·

Published

2026-08-05

·

Updated

2026-08-05

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Contest Gallery WordPress plugin versions prior to 30.0.7
Description The plugin fails to route its front-end login through the standard WordPress authentication flow. Instead, it issues an authentication cookie immediately after the password check. This behavior bypasses installed two-factor authentication and brute-force protection, allowing unlimited and unthrottled password guessing against any account, including administrators, which can lead to full account takeover.
Recommendations Update Contest Gallery WordPress plugin to version 30.0.7 or later.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16055

Affected Products

Contest Gallery