Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-107120

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Oct 10, 2026
Vendor unknown

Description

The Contest Gallery WordPress plugin before 33.0.1 does not limit the number of attempts against its front-end registration email-verification step, which relies on a short numeric PIN, allowing unauthenticated attackers to brute-force the PIN and create and activate a WordPress account bound to an email address they do not own, gaining an authenticated session.

References