CVE-2026-107120
Received Received - Intake

Unauthenticated Account Creation via PIN Brute-Force in Contest Gallery WordPress Plugin

Vulnerability report for CVE-2026-107120, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-10

Last updated on: 2026-10-10

Assigner: WPScan

Description

The Contest Gallery WordPress plugin before 33.0.1 does not limit the number of attempts against its front-end registration email-verification step, which relies on a short numeric PIN, allowing unauthenticated attackers to brute-force the PIN and create and activate a WordPress account bound to an email address they do not own, gaining an authenticated session.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-10
Last Modified
2026-10-10
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Contest Gallery 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Contest Gallery WordPress plugin before version 33.0.1. It allows unauthenticated attackers to bypass email verification by brute-forcing a short numeric PIN used during front-end registration. This grants attackers the ability to create and activate WordPress accounts linked to email addresses they do not own, resulting in unauthorized authenticated sessions.

Detection Guidance

Check if the Contest Gallery WordPress plugin version is below 33.0.1. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files for version details in the plugin header.

Impact Analysis

If you use the vulnerable version of the Contest Gallery plugin, attackers could exploit this to gain unauthorized access to your WordPress site. They could create accounts under fake or stolen email addresses, potentially leading to data breaches, unauthorized content changes, or further attacks on your site or users.

Compliance Impact

This vulnerability could lead to unauthorized account creation, which may violate compliance requirements such as GDPR (data protection) or HIPAA (health data security) by allowing access to sensitive data without proper authorization. It undermines user authentication controls required by these standards.

Mitigation Strategies

Update the Contest Gallery plugin to version 33.0.1 or later immediately. If updating is not possible, consider disabling the plugin until an update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107120. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart