CVE-2026-16057
N/A
N/A
Summary
The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts, pages, and other content they do not own.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Contest Gallery | 0 < 30.0.7 | affected |
Weaknesses
- CWE-862 Missing Authorization
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.