CVE-2026-16057: Contest Gallery < 30.0.7 - Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library
The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gating it only by a coarse role-membership test, which allows any Author-level or higher user to permanently delete arbitrary posts, pages, and other content they do not own.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16057?
The severity of CVE-2026-16057 is rated as 57 on the risk scale.
How do I fix CVE-2026-16057?
To fix CVE-2026-16057, update the Contest Gallery WordPress plugin to version 30.0.7 or higher.
Who is affected by CVE-2026-16057?
Any WordPress site using the Contest Gallery plugin prior to version 30.0.7 is affected by CVE-2026-16057.
What types of content can be deleted due to CVE-2026-16057?
CVE-2026-16057 allows Author-level or higher users to permanently delete arbitrary posts, pages, and other content.
Is there any workaround for CVE-2026-16057?
There are no recommended workarounds for CVE-2026-16057 other than updating the plugin.