What is CVE-2026-16056?
CVE-2026-16056 is a vulnerability in the Contest Gallery WordPress plugin versions prior to 30.0.7. Due to missing capability and nonce checks in one of its handlers, any authenticated user, including Subscribers, can read the site's entire stored OpenAI prompt history. Updating to the latest plugin version is strongly recommended.
Azərbaycanca: CVE-2026-16056, Contest Gallery WordPress plaginində 30.0.7 versiyasından əvvəlki versiyalarda aşkar edilmiş bir boşluqdur. Handler-lərdən birində capability və nonce yoxlaması aparılmadığı üçün, Subscriber daxil olmaqla istənilən autentifikasiya olunmuş istifadəçi saytın OpenAI prompt tarixçəsini oxuya bilər. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which WordPress plugin is affected by CVE-2026-16056?
This vulnerability was found in the Contest Gallery WordPress plugin versions prior to 30.0.7.
What can a user with the Subscriber role do by exploiting CVE-2026-16056?
Due to missing capability and nonce checks in the handlers, any authenticated user, including Subscribers, can read the site's stored OpenAI prompt history.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.