CVE-2026-16057
Contest Gallery < 30.0.7 - Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts, pages, and other content they do not own.
| Vendor | unknown |
| Product | contest gallery |
| Published | Aug 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown contest gallery
Be the first to know when new unknown vulnerabilities affecting unknown contest gallery are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Contest Gallery
0 < 30.0.7
References
Credits
Sai Praneeth Koti WPScan