Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-16056

Опубликовано: 04 авг. 2026
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history.

EPSS

Процентиль: 6%
0.00162
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.3
github
8 дней назад

The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site's entire stored OpenAI prompt history.

EPSS

Процентиль: 6%
0.00162
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862