What is CVE-2026-16586?
CVE-2026-16586 is a Second-Order SQL Injection vulnerability in the Contest Gallery plugin for WordPress (up to version 30.0.7). The flaw occurs when a payload stored in the database via the 'cg_multiple_files_for_post' parameter (as 'cgRealId') is later used in an SQL query without proper escaping. Updating the plugin to the latest version is recommended.
Azərbaycanca: CVE-2026-16586, WordPress üçün Contest Gallery plaginində (30.0.7 və əvvəlki versiyalar) Second-Order SQL Injection zəifliyidir. Bu, `cg_multiple_files_for_post` parametri vasitəsilə verilənlər bazasına `cgRealId` adı ilə yazılan payloadın sonradan işlənməsi zamanı SQL sorğusuna müdaxiləyə səbəb olur. Plagini son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Through which parameter is CVE-2026-16586 exploited in the Contest Gallery plugin?
The vulnerability is exploited via the 'cg_multiple_files_for_post' parameter, where a payload stored as 'cgRealId' in the database is later used in an SQL query.
What should be done to remediate CVE-2026-16586?
It is recommended to update the Contest Gallery plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.