Unrated severityNVD Advisory· Published Aug 4, 2026· Updated Aug 4, 2026
Contest Gallery < 30.0.7 - Subscriber+ OpenAI Prompt History Disclosure via post_cg_get_openai_prompts
CVE-2026-16056
Description
The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history.
Affected products
1- Range: <30.0.7
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/53aec8d3-da17-4183-91b3-73b45681fd20/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.