Vulnerability Description
The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery WordPress plugin before 30.0.7 and enables unlimited, unthrottled password guessing against any account (including administrators) up to full account takeover.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-16055?
CVE-2026-16055 is a vulnerability with a CVSS score of 7.5 (HIGH). The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password ...
How severe is CVE-2026-16055?
CVE-2026-16055 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-16055?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.