๐Ÿ” CVE Alert

CVE-2026-16055

UNKNOWN 0.0

Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_login

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery WordPress plugin before 30.0.7 and enables unlimited, unthrottled password guessing against any account (including administrators) up to full account takeover.

Vendor unknown
Product contest gallery
Published Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for unknown contest gallery

Be the first to know when new unknown vulnerabilities affecting unknown contest gallery are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Contest Gallery
0 < 30.0.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/fa83e5a0-ed6a-4043-8df3-8654bb354a99/

Credits

Muni Nitish Kumar Yaddala WPScan