← Back to search

CVE-2026-16055

7.5 HIGH

Published 2026-08-05 · Updated 2026-08-05

AI risk analysis

Summary
The flaw allows direct authentication cookie issuance post-password check, bypassing security measures and enabling unthrottled password guessing.
Exploitability
Exploitation is relatively easy with preconditions of having access to user login attempts.
Blast radius
If exploited, it can lead to full account takeover for any user, including administrators.
Prioritized remediation
Update to Contest Gallery WordPress plugin version 30.0.7 or later immediately.
auth-bypasswp-pluginsecurity-update

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery WordPress plugin before 30.0.7 and enables unlimited, unthrottled password guessing against any account (including administrators) up to full account takeover.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-287

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.