{"id":"CVE-2026-16055","published":"2026-08-05T07:16:35.463","lastModified":"2026-08-05T15:16:36.967","description":"The Contest Gallery  WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery  WordPress plugin before 30.0.7 and enables unlimited, unthrottled password guessing against any account (including administrators) up to full account takeover.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-287"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/fa83e5a0-ed6a-4043-8df3-8654bb354a99/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows direct authentication cookie issuance post-password check, bypassing security measures and enabling unthrottled password guessing.","exploitability":"Exploitation is relatively easy with preconditions of having access to user login attempts.","blast_radius":"If exploited, it can lead to full account takeover for any user, including administrators.","remediation":"Update to Contest Gallery WordPress plugin version 30.0.7 or later immediately.","tags":["auth-bypass","wp-plugin","security-update"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:57:12.956Z"}}