WordPress Plugin Vulnerabilities

Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_login

Description

The plugin does not route its front-end login through the standard WordPress authentication flow, issuing an authentication cookie directly after the password check, which bypasses installed brute-force-protection and two-factor-authentication plugins and enables unlimited, unthrottled password guessing against any account (including administrators) up to full account takeover.

Proof of Concept

Affects Plugins

Fixed in 30.0.7

References

Classification

Miscellaneous

Original Researcher
Muni Nitish Kumar Yaddala
Submitter
Muni Nitish Kumar Yaddala
Verified
Yes

Timeline

Publicly Published
2026-07-29 (about 28 days ago)
Added
2026-07-29 (about 28 days ago)
Last Updated
2026-07-29 (about 28 days ago)

Other