CVE-2026-16056

Published: Ago 04, 2026 Last Modified: Ago 04, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history.

https://wpscan.com/vulnerability/53aec8d3-da17-4183-91b3-73b45681fd20/