Registrationmagic

WordPress plugin · registrationmagic · WordPress.org ↗
0
Critical
2
High
8
Known total
0
Unfixed
Running Registrationmagic on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
HIGH
CVSS 8.8
RegistrationMagic 5.0.1.8 - 6.0.9.8 - Unauthenticated Authentication Bypass via Missing Facebook Token Audience Validation
CVE.org
>=5.0.1.8, <6.0.9.9 v6.0.9.9 CVE-2026-77826 Sep 5, 2026
HIGH
CVSS 7.5
RegistrationMagic < 6.0.9.9 - Unauthenticated Stored XSS via Rating Field
CVE.org
>=0, <6.0.9.9 v6.0.9.9 CVE-2026-77792 Sep 2, 2026
MEDIUM
CVSS 5.3
RegistrationMagic 6.0.0.0 - 6.0.9.8 - Unauthenticated Payment Bypass via Zero Quantity
CVE.org
>=6.0.0.0, <6.0.9.9 v6.0.9.9 CVE-2026-77794 Sep 2, 2026
MEDIUM
CVSS 5.3
RegistrationMagic < 6.0.9.9 - Unauthenticated Payment Bypass via Omitted Price Field
CVE.org
>=0, <6.0.9.9 v6.0.9.9 CVE-2026-77793 Sep 2, 2026
MEDIUM
CVSS 5.5
RegistrationMagic < 6.0.9.4 - Admin+ SQLi via 'rm_sortby' Parameter
CVE.org
>=0, <6.0.9.4 v6.0.9.4 CVE-2026-77790 Aug 26, 2026
MEDIUM
CVSS 5.3
RegistrationMagic < 6.0.9.5 - Unauthenticated Payment Bypass via Amount-Blind PayPal Verification
CVE.org
>=0, <6.0.9.5 v6.0.9.5 CVE-2026-15208 Aug 6, 2026
MEDIUM
CVSS 5.3
RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission Disclosure via IDOR
CVE.org
>=0, <6.0.9.4 v6.0.9.4 CVE-2026-15255 Jul 30, 2026
MEDIUM
CVSS 5.3
RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission and User Profile Modification
CVE.org
>=0, <6.0.9.4 v6.0.9.4 CVE-2026-15257 Jul 30, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.