๐Ÿ” CVE Alert

CVE-2026-107120

UNKNOWN 0.0

Contest Gallery < 33.0.1 - Unauthenticated Email Verification Bypass via Brute-Forceable Registration PIN

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Contest Gallery WordPress plugin before 33.0.1 does not limit the number of attempts against its front-end registration email-verification step, which relies on a short numeric PIN, allowing unauthenticated attackers to brute-force the PIN and create and activate a WordPress account bound to an email address they do not own, gaining an authenticated session.

Vendor unknown
Product contest gallery
Published Oct 10, 2026
Stay Ahead of the Next One

Get instant alerts for unknown contest gallery

Be the first to know when new unknown vulnerabilities affecting unknown contest gallery are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Contest Gallery
0 < 33.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/13853303-741e-4f87-8543-d5d825d20e8e/

Credits

Akshat Parikh (SN1PER) WPScan