CVE-2026-16056

The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-04 07:16

Updated : 2026-08-26 16:31


NVD link : CVE-2026-16056

Mitre link : CVE-2026-16056

CVE.ORG link : CVE-2026-16056


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization