What is CVE-2026-16055?
CVE-2026-16055 affects the Contest Gallery WordPress plugin versions before 30.0.7. The vulnerability bypasses the standard WordPress authentication flow by issuing an authentication cookie directly after a password check, thus circumventing installed brute-force protection and two-factor authentication mechanisms. Users should update the plugin to version 30.0.7 or later.
Azərbaycanca: CVE-2026-16055, Contest Gallery WordPress plaginin 30.0.7-dən əvvəlki versiyalarında aşkarlanıb. Zəiflik autentifikasiya axını ilə bağlıdır — plagin standart WordPress giriş mexanizmini keçərək birbaşa kuki verir, bu da quraşdırılmış brute-force müdafiəsi və iki faktorlu autentifikasiyanı (2FA) sıradan çıxarır. İstifadəçilərə plaqini ən azı 30.0.7 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of the Contest Gallery WordPress plugin are affected by CVE-2026-16055?
All versions before 30.0.7 are affected by this vulnerability.
How does the CVE-2026-16055 vulnerability bypass security measures like two-factor authentication (2FA)?
The vulnerability bypasses the standard WordPress authentication flow by issuing an authentication cookie directly after a password check, thus circumventing installed brute-force protection and 2FA mechanisms.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.