Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 04 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics |
cvssV3_1
|
Mon, 03 Aug 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Contest-gallery
Contest-gallery contest Gallery Wordpress Wordpress wordpress |
|
| Vendors & Products |
Contest-gallery
Contest-gallery contest Gallery Wordpress Wordpress wordpress |
Mon, 03 Aug 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts, pages, and other content they do not own. | |
| Title | Contest Gallery < 30.0.7 - Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-04T17:42:06.222Z
Reserved: 2026-07-17T12:05:48.224Z
Link: CVE-2026-16057
Updated: 2026-08-04T15:59:41.937Z
Status : Received
Published: 2026-08-03T07:16:40.523
Modified: 2026-08-04T18:16:45.833
Link: CVE-2026-16057
No data.
OpenCVE Enrichment
Updated: 2026-08-04T21:30:12Z