Description
The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts, pages, and other content they do not own.
Published:
2026-08-03
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 03 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Contest-gallery
Contest-gallery contest Gallery Wordpress Wordpress wordpress |
|
| Vendors & Products |
Contest-gallery
Contest-gallery contest Gallery Wordpress Wordpress wordpress |
Mon, 03 Aug 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts, pages, and other content they do not own. | |
| Title | Contest Gallery < 30.0.7 - Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-03T06:00:10.227Z
Reserved: 2026-07-17T12:05:48.224Z
Link: CVE-2026-16057
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-03T07:30:04Z
Weaknesses
No weakness.