{"id":"CVE-2026-107120","title":"The Contest Gallery  WordPress plugin before 33.0.1 does not limit the number of attempts against its front-end registration email-verification step, which relies on a short numeric PIN, allowing unauthenticated attackers to brute-force …","summary":"The Contest Gallery  WordPress plugin before 33.0.1 does not limit the number of attempts against its front-end registration email-verification step, which relies on a short numeric PIN, allowing unauthenticated attackers to brute-force …","severity":"none","published":"2026-10-10","updated":"2026-10-10","sourceUpdated":"2026-10-10T06:16:40.903","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107120","references":[{"url":"https://wpscan.com/vulnerability/13853303-741e-4f87-8543-d5d825d20e8e/","label":"contact@wpscan.com"}],"tags":["nvd"],"ingestedAt":"2026-10-10T06:24:42.864Z","slug":"CVE-2026-107120","body":"## Overview\n\nThe Contest Gallery  WordPress plugin before 33.0.1 does not limit the number of attempts against its front-end registration email-verification step, which relies on a short numeric PIN, allowing unauthenticated attackers to brute-force the PIN and create and activate a WordPress account bound to an email address they do not own, gaining an authenticated session.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}