Loading market data...
← Back to CVE feed

CVE-2026-16056

MEDIUM CVSS 4.3 View on NVD ↗

Description

The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Published: Aug 04, 2026 07:16 UTC Modified: Aug 04, 2026 18:16 UTC