CVE-2026-16055: Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_login
The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery WordPress plugin before 30.0.7 and enables unlimited, unthrottled password guessing against any account (including administrators) up to full account takeover.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/contest-galleryto a version that resolves this vulnerability.Fixed in 30.0.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16055?
CVE-2026-16055 has a risk score of 78, indicating a high severity vulnerability.
How do I fix CVE-2026-16055?
To fix CVE-2026-16055, update the Contest Gallery WordPress plugin to version 30.0.7 or higher.
What type of vulnerability is CVE-2026-16055?
CVE-2026-16055 is an unauthenticated login-protection and two-factor authentication bypass vulnerability.
What systems are affected by CVE-2026-16055?
CVE-2026-16055 affects the Contest Gallery plugin for WordPress prior to version 30.0.7.
What impact does CVE-2026-16055 have?
CVE-2026-16055 allows attackers to bypass brute-force protection and two-factor authentication.