CVE-2026-107120: Unknown Contest Gallery
Medium severity, CVSS 5.3. EPSS: 0.1% chance of exploitation in the next 30 days.
The Contest Gallery WordPress plugin before 33.0.1 does not limit the number of attempts against its front-end registration email-verification step, which relies on a short numeric PIN, allowing unauthenticated attackers to brute-force the PIN and create and activate a WordPress account bound to an email address they do not own, gaining an authenticated session.
Affected products
- Unknown Contest Gallery: before 33.0.1 (fixed in 33.0.1)
Published 2026-10-10. Last modified 2026-10-10.