CVE-2026-16056
Received Received - Intake

Authenticated Users Can Access OpenAI Prompt History in Contest Gallery WordPress Plugin

Vulnerability report for CVE-2026-16056, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-04

Last updated on: 2026-08-04

Assigner: WPScan

Description

The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-04
Last Modified
2026-08-04
Generated
2026-08-04
AI Q&A
2026-08-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
the_contest_gallery wordpress_plugin to 30.0.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Contest Gallery WordPress plugin before version 30.0.7 has a vulnerability where it fails to check user capabilities or nonces in a specific handler. This allows any authenticated user, even those with Subscriber-level access, to read the entire stored OpenAI prompt history of the site.

Detection Guidance

Check if the Contest Gallery WordPress plugin is installed and verify its version. If it is below 30.0.7, the vulnerability likely exists. Inspect WordPress user roles for unauthorized access to OpenAI prompt history.

Impact Analysis

This vulnerability could expose sensitive information stored in OpenAI prompts, including proprietary data, user interactions, or internal processes. Attackers with minimal access could extract this data, leading to potential data breaches or misuse of confidential information.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, or other privacy regulations by exposing sensitive personal or health data. Organizations may face legal penalties, fines, or reputational damage due to unauthorized data access.

Mitigation Strategies

Update the Contest Gallery WordPress plugin to version 30.0.7 or later to address the missing capability and nonce checks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16056. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart