CVE-2026-16055
Received Received - Intake

Authentication Bypass in Contest Gallery WordPress Plugin

Vulnerability report for CVE-2026-16055, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: WPScan

Description

The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery WordPress plugin before 30.0.7 and enables unlimited, unthrottled password guessing against any account (including administrators) up to full account takeover.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
contest_gallery contest_gallery to 30.0.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Contest Gallery WordPress plugin before version 30.0.7 has a vulnerability where it does not use WordPress's standard login process. Instead, it directly issues an authentication cookie after checking the password, bypassing security measures like brute-force protection and two-factor authentication. This allows attackers to repeatedly guess passwords without restrictions, potentially taking over any account including administrators.

Detection Guidance

Check the installed version of the Contest Gallery plugin in your WordPress admin panel. If it is below 30.0.7, the vulnerability is present. You can also inspect login requests to see if authentication cookies are issued directly after password checks without standard WordPress authentication flow.

Impact Analysis

This vulnerability allows unauthenticated attackers to gain full control over any account on your WordPress site, including admin accounts. They can bypass security protections and repeatedly attempt to guess passwords without limits, leading to potential data breaches, unauthorized access, and complete site compromise.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements under GDPR, HIPAA, and other regulations. It may result in data breaches, unauthorized data exposure, and failure to meet security control standards, potentially leading to legal penalties and reputational damage.

Mitigation Strategies

Update the Contest Gallery plugin to version 30.0.7 or later immediately. Disable front-end login functionality if not required until the update is applied. Monitor login attempts for unusual activity indicating brute-force attacks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16055. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart