CVE-2026-16057
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/08/2026
Last modified:
04/08/2026
Description
The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts, pages, and other content they do not own.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM



