cvedb.io
CVE-2026-16057
UNKNOWN · CVSS n/a
EPSS exploitation probability: 0%
Published 2026-08-03T07:16:40.523 · Last modified 2026-08-03T07:16:40.523

Summary

The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts, pages, and other content they do not own.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.