← WordPress Vulnerabilities
WordPress security by component

RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login

RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is a WordPress component with 37 published CVE records in this archive. The latest tracked vulnerability was published Jul 01, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: custom-registration-form-builder-with-submission-manager

CVE-2026-12158: RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: Cross-site request forgery

RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 6.0.9.1.

PublishedJul 01, 2026
Known safe version> 6.0.9.1
Safe version
Jul 01, 2026 CVE-2026-12158
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: Cross-site request forgery
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 6.0.9.1.
> 6.0.9.1
CVE8.8
NVDPending
Jun 27, 2026 CVE-2026-9242
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: Privilege escalation or authentication bypass
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 6.0.8.6.
> 6.0.8.6
CVE5.3
NVDPending
Jun 15, 2026 CVE-2026-49764
RegistrationMagic: A security weakness
RegistrationMagic is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 6.0.8.6.
6.0.8.7
CVE9.8
NVDPending
Mar 25, 2026 CVE-2026-32498
RegistrationMagic: A security weakness
RegistrationMagic is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through <= 6.0.7.6.
6.0.7.7
CVE7.5
NVDPending
Mar 25, 2026 CVE-2026-24373
RegistrationMagic: Privilege escalation or authentication bypass
RegistrationMagic is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 6.0.7.1.
6.0.7.2
CVE8.1
NVDPending
Mar 13, 2026 CVE-2026-32385
RegistrationMagic: A security weakness
RegistrationMagic is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Feb 18, 2026 CVE-2025-14444
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: A security weakness
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jan 28, 2026 CVE-2026-1054
RegistrationMagic: A security weakness
RegistrationMagic is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Jan 22, 2026 CVE-2026-24374
RegistrationMagic: Cross-site request forgery
RegistrationMagic is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVDPending
Jan 17, 2026 CVE-2025-15403
RegistrationMagic: Privilege escalation or authentication bypass
RegistrationMagic is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending
Oct 08, 2025 CVE-2025-11204
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: SQL injection
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVDPending
Apr 04, 2025 CVE-2025-2836
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: Cross-site scripting
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is affected by cross-site scripting. Exploitation requires at least subscriber-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Nov 09, 2024 CVE-2024-10508
RegistrationMagic – User Registration Plugin with Custom Registration Forms: Privilege escalation or authentication bypass
RegistrationMagic – User Registration Plugin with Custom Registration Forms is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending
Aug 19, 2024 CVE-2024-43317
RegistrationMagic: Cross-site scripting
RegistrationMagic is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.3
NVD6.1
Aug 01, 2024 CVE-2024-39643
RegistrationMagic: Cross-site scripting
RegistrationMagic is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.8
NVD6.1
Jun 04, 2024 CVE-2023-51544
RegistrationMagic: A security weakness
RegistrationMagic is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Jun 04, 2024 CVE-2023-51543
RegistrationMagic: Privilege escalation or authentication bypass
RegistrationMagic is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE5.3
NVD7.5
May 03, 2024 CVE-2024-33947
RegistrationMagic: Cross-site scripting
RegistrationMagic is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Apr 24, 2024 CVE-2023-23989
RegistrationMagic: Cross-site scripting
RegistrationMagic is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.3
NVD6.5
Apr 24, 2024 CVE-2023-23976
RegistrationMagic: A security weakness
RegistrationMagic is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Apr 11, 2024 CVE-2024-25935
RegistrationMagic: A security weakness
RegistrationMagic is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD9.8
Apr 09, 2024 CVE-2024-1991
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: Privilege escalation or authentication bypass
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is affected by privilege escalation or authentication bypass. Exploitation requires at least subscriber-level access. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
Mar 26, 2024 CVE-2024-2951
RegistrationMagic: Cross-site request forgery
RegistrationMagic is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Mar 19, 2024 CVE-2024-29113
RegistrationMagic: Cross-site scripting
RegistrationMagic is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Feb 01, 2024 CVE-2023-51509
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: Cross-site scripting
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Dec 28, 2023 CVE-2023-50846
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: SQL injection
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVD7.2
Nov 30, 2023 CVE-2023-47645
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: Cross-site request forgery
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
May 16, 2023 CVE-2023-2548
RegistrationMagic: A security weakness
RegistrationMagic is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.6
NVD7.2
May 16, 2023 CVE-2023-2499
RegistrationMagic: Privilege escalation or authentication bypass
RegistrationMagic is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVD9.8
Mar 13, 2023 CVE-2023-25991
Custom Registration Form Builder With Submission Manager: Cross-site request forgery
Custom Registration Form Builder With Submission Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD8.8
Mar 12, 2020 CVE-2020-8436
Custom Registration Form Builder With Submission Manager: Cross-site scripting
Custom Registration Form Builder With Submission Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Mar 12, 2020 CVE-2020-8435
Custom Registration Form Builder With Submission Manager: SQL injection
Custom Registration Form Builder With Submission Manager is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.1
NVD8.1
Mar 06, 2020 CVE-2020-9458
Custom Registration Form Builder With Submission Manager: A security weakness
Custom Registration Form Builder With Submission Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.8
NVD8.8
Mar 06, 2020 CVE-2020-9457
Custom Registration Form Builder With Submission Manager: Privilege escalation or authentication bypass
Custom Registration Form Builder With Submission Manager is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVD8.8
Mar 06, 2020 CVE-2020-9456
Custom Registration Form Builder With Submission Manager: A security weakness
Custom Registration Form Builder With Submission Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.8
NVD8.8
Mar 06, 2020 CVE-2020-9455
Custom Registration Form Builder With Submission Manager: A security weakness
Custom Registration Form Builder With Submission Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Mar 06, 2020 CVE-2020-9454
Custom Registration Form Builder With Submission Manager: Cross-site request forgery
Custom Registration Form Builder With Submission Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE8.8
NVD8.8