CVE-2026-16056: The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handler
Summary
The Contest Gallery WordPress plugin before version 30.0.7 has a security flaw where it fails to check permissions and nonces (security tokens that prevent unauthorized actions) in one of its functions, allowing any logged-in user, even those with minimal access (Subscriber role), to view all stored OpenAI prompt history on the website.
Solution / Mitigation
Update the Contest Gallery WordPress plugin to version 30.0.7 or later.
Vulnerability Details
EPSS: 0.0%
August 4, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-16056
First tracked: August 4, 2026 at 08:08 AM
Classified by LLM (prompt v3) · confidence: 85%