The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery WordPress plugin before 30.0.7 and enables unlimited, unthrottled password guessing against any account (including administrators) up to full account takeover.
Metrics
Affected Vendors & Products
References
History
Wed, 05 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 05 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Contest-gallery
Contest-gallery contest Gallery Wordpress Wordpress wordpress |
|
| Weaknesses | CWE-287 | |
| Vendors & Products |
Contest-gallery
Contest-gallery contest Gallery Wordpress Wordpress wordpress |
Wed, 05 Aug 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery WordPress plugin before 30.0.7 and enables unlimited, unthrottled password guessing against any account (including administrators) up to full account takeover. | |
| Title | Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_login | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-05T14:04:53.010Z
Reserved: 2026-07-17T12:05:43.862Z
Link: CVE-2026-16055
Updated: 2026-08-05T14:01:23.983Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T15:30:17Z