What is CVE-2026-16057?
A critical missing authorization vulnerability has been found in the Contest Gallery WordPress plugin (versions prior to 30.0.7). The flaw allows any Author-level or higher user to permanently delete arbitrary posts and pages due to insufficient per-object capability and nonce checks. Immediate update of the plugin to the latest version is strongly recommended.
Azərbaycanca: WordPress üçün Contest Gallery plaginində (30.0.7-dən əvvəlki versiyalar) kritik səlahiyyət yoxlaması zəifliyi aşkar edilib. Bu boşluq 'Author' və ya daha yüksək səviyyəli istənilən istifadəçiyə sistemdəki ixtiyari post və səhifələri qalıcı olaraq silməyə imkan verir. Plaginin dərhal ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Contest Gallery plugin are affected by CVE-2026-16057?
All versions of the Contest Gallery plugin prior to 30.0.7 are affected by this vulnerability.
What user permission level is required to exploit this vulnerability?
Exploiting this vulnerability requires Author-level or higher user permissions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.