WordPress Plugin Vulnerabilities

Contest Gallery < 33.0.1 - Unauthenticated Email Verification Bypass via Brute-Forceable Registration PIN

Description

The plugin does not limit the number of attempts against its front-end registration email-verification step, which relies on a short numeric PIN, allowing unauthenticated attackers to brute-force the PIN and create and activate a WordPress account bound to an email address they do not own, gaining an authenticated session.

Proof of Concept

Affects Plugins

Fixed in 33.0.1

References

Classification

Miscellaneous

Original Researcher
Akshat Parikh (SN1PER)
Submitter
Akshat Parikh (SN1PER)
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-10-08 (about 2 days ago)
Added
2026-10-08 (about 1 day ago)
Last Updated
2026-10-08 (about 1 day ago)

Other