Description
The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery WordPress plugin before 30.0.7 and enables unlimited, unthrottled password guessing against any account (including administrators) up to full account takeover.
Published: 2026-08-05
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Contest Gallery WordPress plugin as deployed before version 30.0.7 does not use the standard WordPress authentication mechanism. After a password check it issues an authentication cookie directly, bypassing any brute‑force protection and two‑factor‑authentication that might be installed on the site. Because of this bypass, an attacker can perform unlimited, unthrottled password guessing against any user account, including administrators, and eventually gain full account takeover.

Affected Systems

All installations of the Contest Gallery WordPress plugin that are running a version older than 30.0.7. The vendor is an unknown organization hosting the plugin under the name 'Contest Gallery'.

Risk and Exploitability

The vulnerability allows an attacker to bypass authentication safeguards and take over accounts. The CVSS score is not provided in the CVE entry. EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. Nonetheless, because the plugin does not enforce login throttling and two‑factor authentication, the risk of exploitation is high, particularly for sites where the plugin is enabled and the default WordPress login protection is not configured.

Generated by OpenCVE AI on August 5, 2026 at 07:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Contest Gallery WordPress plugin to version 30.0.7 or newer.
  • If upgrading is not immediately possible, disable the plugin’s dedicated login endpoint or remove the plugin entirely until a patch is applied.
  • Ensure that your WordPress installation has brute‑force protection and two‑factor authentication enabled to reduce the impact of any unpatched login route.
  • Monitor login activity for suspicious patterns and review logs for repeated brute‑force attempts.

Generated by OpenCVE AI on August 5, 2026 at 07:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Contest-gallery
Contest-gallery contest Gallery
Wordpress
Wordpress wordpress
Weaknesses CWE-287
Vendors & Products Contest-gallery
Contest-gallery contest Gallery
Wordpress
Wordpress wordpress

Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication Contest Gallery WordPress plugin before 30.0.7 and enables unlimited, unthrottled password guessing against any account (including administrators) up to full account takeover.
Title Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_login
References

Subscriptions

Contest-gallery Contest Gallery
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-05T06:00:12.744Z

Reserved: 2026-07-17T12:05:43.862Z

Link: CVE-2026-16055

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T07:30:16Z

Weaknesses