CVE-2026-16057 PUBLISHED

Contest Gallery < 30.0.7 - Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library

Assigner: WPScan
Reserved: 17.07.2026 Published: 03.08.2026 Updated: 03.08.2026

The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts, pages, and other content they do not own.

Product Status

Vendor Unknown
Product Contest Gallery
Versions Default: unaffected
  • affected from 0 to 30.0.7 (excl.)

Credits

  • Sai Praneeth Koti finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE