AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16055

HIGH · CVSS 7.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Contest Gallery plugin for WordPress versions prior to 30.0.7 is vulnerable due to its failure to utilize the standard WordPress authentication flow, allowing direct issuance of authentication cookies post-password verification. This flaw permits unlimited and unthrottled password guessing attacks, potentially leading to full account takeover, including for administrative accounts. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of unauthorized access.

CVE
CVE-2026-16055
Severity
HIGH
CVSS
7.5
EPSS
0.30%
WordPress

Original NVD Description

The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery WordPress plugin before 30.0.7 and enables unlimited, unthrottled password guessing against any account (including administrators) up to full account takeover.