Unrated severityNVD Advisory· Published Oct 10, 2026
CVE-2026-107120
CVE-2026-107120
Description
The Contest Gallery WordPress plugin before 33.0.1 does not limit the number of attempts against its front-end registration email-verification step, which relies on a short numeric PIN, allowing unauthenticated attackers to brute-force the PIN and create and activate a WordPress account bound to an email address they do not own, gaining an authenticated session.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <33.0.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.