CyberRota Analysis
AI-GeneratedThe Contest Gallery plugin for WordPress versions prior to 30.0.7 is vulnerable due to a lack of capability and nonce checks, enabling any authenticated user, including those with Subscriber privileges, to access the site's complete OpenAI prompt history. This exposure could lead to unauthorized data access and potential privacy breaches. WordPress site administrators and security teams should prioritize updating this plugin to mitigate the risk of sensitive information disclosure.
Original NVD Description
The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history.