Security Advisory

CVE-2026-16055

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-05 06:00:12
Last updated 2026-08-05 14:04:53
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery WordPress plugin before 30.0.7 and enables unlimited, unthrottled password guessing against any account (including administrators) up to full account takeover.