VYPR
Medium severity4.3NVD Advisory· Published Aug 4, 2026· Updated Aug 26, 2026

CVE-2026-16056

CVE-2026-16056

Description

The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

2