CVE-2026-107120
Contest Gallery < 33.0.1 - Unauthenticated Email Verification Bypass via Brute-Forceable Registration PIN
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Contest Gallery WordPress plugin before 33.0.1 does not limit the number of attempts against its front-end registration email-verification step, which relies on a short numeric PIN, allowing unauthenticated attackers to brute-force the PIN and create and activate a WordPress account bound to an email address they do not own, gaining an authenticated session.
| Vendor | unknown |
| Product | contest gallery |
| Published | Oct 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown contest gallery
Be the first to know when new unknown vulnerabilities affecting unknown contest gallery are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Contest Gallery
0 < 33.0.1
References
Credits
Akshat Parikh (SN1PER) WPScan