CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-107120: Contest Gallery 0 to before 33.0.1

Affected technology

Contest Gallery · 0 to before 33.0.1
Vendor not specified by the source

Description’s affected range: before 33.0.1 does not limit the number of attempts against its front-end registration email-verification step

Component: Not specified by the source

What an attacker can do

Unauthenticated attackers can brute-force the PIN and create and activate a WordPress account bound to an email address they do not own, gaining an authenticated session.

Published

KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-107120.html