Sceawere
Vulnerability Detail
CVE-2026-107120UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Contest Gallery PIN Brute-Force Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Contest Gallery
- Attack Type
- CWE-287 Improper Authentication
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Contest Gallery WordPress plugin before 33.0.1 does not limit the number of attempts against its front-end registration email-verification step, which relies on a short numeric PIN, allowing unauthenticated attackers to brute-force the PIN and create and activate a WordPress account bound to an email address they do not own, gaining an authenticated session.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-10T06:16:40.903Z",
"pubdate": "2026-10-10T06:16:40.903Z",
"executiveSummary": "The Contest Gallery WordPress plugin, in versions prior to 33.0.1, contains an authentication bypass vulnerability stemming from an improperly secured email-verification mechanism.\nThe vulnerability is characterized by a lack of rate-limiting on the front-end registration verification endpoint, which utilizes a short numeric PIN for account activation.\nThis flaw permits unauthenticated remote attackers to perform brute-force attacks against the verification PIN, facilitating the unauthorized creation and activation of WordPress accounts.\nBy successfully brute-forcing the PIN, an attacker can verify an account tied to an email address they do not control, effectively bypassing identity verification controls.\nThe risk is critical as it allows for the creation of unauthorized accounts, potentially leading to unauthorized system access, privilege escalation, or further malicious activity within the WordPress environment.\nExploitation requires no prior authentication and can be executed via network-accessible front-end interfaces.",
"technicalDetails": "The vulnerability resides in the front-end user registration and verification workflow of the Contest Gallery plugin. When a user registers, the system triggers an email verification process requiring the input of a short numeric PIN to finalize account creation.\nThe primary root cause is the absence of request throttling, rate-limiting, or account lockout mechanisms on the verification endpoint. Because the PIN space is limited (being a short numeric string), the implementation is highly susceptible to automated brute-force attacks.\nAn attacker can initiate the registration process for any arbitrary email address and subsequently intercept or observe the verification request. Since the server does not restrict the number of failed attempts or implement exponential backoff, an attacker can programmatically iterate through all possible PIN combinations until the correct value is submitted.\nThe attack flow follows a structured sequence: 1) The attacker initiates an account registration request with a chosen email address. 2) The plugin generates a numeric PIN and sends it to the provided email. 3) The attacker ignores the email delivery and instead targets the verification endpoint by submitting sequential or randomized PINs via automated POST requests. 4) The plugin fails to validate the request rate or frequency, allowing the attacker to cycle through the small entropy space of the numeric PIN. 5) Upon finding the correct PIN, the plugin marks the account as verified and active.\nThe impact of this vulnerability is significant, as it grants unauthenticated attackers the ability to gain an authenticated session. Once the account is activated, the attacker can leverage the account privileges assigned to registered users. Depending on the site configuration, this could facilitate unauthorized access to user-restricted content, bypass site registration gatekeeping, or serve as a vector for secondary attacks targeting other authenticated components or administrative functions within the WordPress installation.\nAffected versions include all iterations of the Contest Gallery plugin prior to 33.0.1. The vulnerability is entirely network-accessible, requires no administrative or user-level privileges, and presents a low barrier to entry for exploitation."
}