Get real-time updates on Telegram
Verified
CVE-2026-107120: Contest Gallery 0 to before 33.0.1
Affected technology
Contest Gallery · 0 to before 33.0.1
Vendor not specified by the source
Description’s affected range: before 33.0.1 does not limit the number of attempts against its front-end registration email-verification step
Component: Not specified by the source
What an attacker can do
Unauthenticated attackers can brute-force the PIN and create and activate a WordPress account bound to an email address they do not own, gaining an authenticated session.
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-10 07:23:45.480922+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-10 06:17:36.054866+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-107120.html