← Späť na vyhľadávanie CVE

CVE-2026-16056

Popis

The Contest Gallery WordPress plugin before 30.0.7 does not perform any capability or nonce check in one of its handlers, allowing any authenticated user down to Subscriber to read the site-s entire stored OpenAI prompt history.

CVSS 4.3EPSS 0.16199999999999998%Riziko 0.44
Zobraziť zdroj
Zverejnené
2026-08-04 07:16:29
Posledná úprava
2026-08-04 18:16:45
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N