CVE-2026-107120
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Oct 10, 2026
Vendor
unknown
Description
The Contest Gallery WordPress plugin before 33.0.1 does not limit the number of attempts against its front-end registration email-verification step, which relies on a short numeric PIN, allowing unauthenticated attackers to brute-force the PIN and create and activate a WordPress account bound to an email address they do not own, gaining an authenticated session.