CVE-2026-16057
Received Received - Intake

Contest Gallery WordPress Plugin Post Deletion Auth Bypass

Vulnerability report for CVE-2026-16057, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: WPScan

Description

The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts, pages, and other content they do not own.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
the_contest_gallery wordpress_plugin to 30.0.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in The Contest Gallery WordPress plugin before version 30.0.7 allows users with Author-level or higher privileges to delete any posts, pages, or other content they do not own. The issue occurs because the plugin fails to perform proper capability or nonce checks in a post-deletion handler, relying only on a broad role-membership test.

Detection Guidance

Check WordPress plugin versions. Use WP-CLI with 'wp plugin list' to verify if Contest Gallery is below 30.0.7. Inspect server logs for unauthorized post deletions by Author-level users.

Impact Analysis

If you are a WordPress site administrator or user with Author-level or higher privileges, an attacker with such access could exploit this flaw to permanently delete your site's content, including posts, pages, or other critical data. This could lead to data loss, disruption of services, or reputational damage.

Mitigation Strategies

Update the Contest Gallery plugin to version 30.0.7 or higher immediately. Review user roles and remove unnecessary Author-level permissions. Monitor for unauthorized content deletions in logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16057. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart