Feed/CVE-2026-16057
CVE-2026-16057MEDIUMCVSS 6.5

CVE-2026-16057

Published Aug 3, 2026·Updated Aug 4, 2026

NVD Description

The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts, pages, and other content they do not own.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free