CVE-2026-16055
Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_login
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery WordPress plugin before 30.0.7 and enables unlimited, unthrottled password guessing against any account (including administrators) up to full account takeover.
| Vendor | unknown |
| Product | contest gallery |
| Published | Aug 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown contest gallery
Be the first to know when new unknown vulnerabilities affecting unknown contest gallery are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Contest Gallery
0 < 30.0.7
References
Credits
Muni Nitish Kumar Yaddala WPScan