Detects Contest Gallery WordPress plugin versions 28.1.5 or earlier. The email confirmation handler uses the user's email string in a WHERE ID = %s clause instead of the numeric user ID. MySQL silently coerces an email like '[email protected]' to integer 1 (the admin user ID), overwriting the admin's user_activation_key. An unauthenticated AJAX endpoint (post_cg1l_login_user_by_key) then authenticates any user by activation key lookup, granting full admin access. Requires non-default RegMailOptional=1 setting. The fix in 28.1.6 uses absint() for the WHERE clause and switches to get_user_meta() with hash_equals() for key-based login.
Is your app exploitable through CVE-2026-4021?
Scan your domain free