CVE-2026-4021 | contest-gallery Contest Gallery Plugin up to 28.1.5 on WordPress user_activation_key improper authentication (EUVD-2026-14654 / CNNVD-202603-4628)
A vulnerability was found in contest-gallery Contest Gallery Plugin up to 28.1.5 on WordPress. It has been declared as critical. Affected by this vulnerability is the function user_activation_key of the file users-registry-check-after-email-or-pin-confirmation.php. The manipulation results in improper authentication.
This vulnerability was named CVE-2026-4021. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.