CVE-2026-107120 PUBLISHED

Contest Gallery < 33.0.1 - Unauthenticated Email Verification Bypass via Brute-Forceable Registration PIN

Assigner: WPScan
Reserved: 07.10.2026 Published: 10.10.2026 Updated: 10.10.2026

The Contest Gallery WordPress plugin before 33.0.1 does not limit the number of attempts against its front-end registration email-verification step, which relies on a short numeric PIN, allowing unauthenticated attackers to brute-force the PIN and create and activate a WordPress account bound to an email address they do not own, gaining an authenticated session.

Product Status

Vendor Unknown
Product Contest Gallery
Versions Default: unaffected
  • affected from 0 to 33.0.1 (excl.)

Credits

  • Akshat Parikh (SN1PER) finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE