WordPress security by component
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login
Plugin description
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is a WordPress component with 37 published CVE records in this archive. The latest tracked vulnerability was published Jul 01, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
custom-registration-form-builder-with-submission-managerLatest vulnerability
CVE-2026-12158: RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: Cross-site request forgery
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 6.0.9.1.
| Safe version |
|
||
|---|---|---|---|
| Jul 01, 2026 |
CVE-2026-12158
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: Cross-site request forgery
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is <= 6.0.9.1.
|
> 6.0.9.1 |
CVE8.8
NVDPending
|
| Jun 27, 2026 |
CVE-2026-9242
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: Privilege escalation or authentication bypass
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 6.0.8.6.
|
> 6.0.8.6 |
CVE5.3
NVDPending
|
| Jun 15, 2026 |
CVE-2026-49764
RegistrationMagic: A security weakness
RegistrationMagic is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 6.0.8.6.
|
6.0.8.7 |
CVE9.8
NVDPending
|
| Mar 25, 2026 |
CVE-2026-32498
RegistrationMagic: A security weakness
RegistrationMagic is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through <= 6.0.7.6.
|
6.0.7.7 |
CVE7.5
NVDPending
|
| Mar 25, 2026 |
CVE-2026-24373
RegistrationMagic: Privilege escalation or authentication bypass
RegistrationMagic is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 6.0.7.1.
|
6.0.7.2 |
CVE8.1
NVDPending
|
| Mar 13, 2026 |
CVE-2026-32385
RegistrationMagic: A security weakness
RegistrationMagic is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Feb 18, 2026 |
CVE-2025-14444
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: A security weakness
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jan 28, 2026 |
CVE-2026-1054
RegistrationMagic: A security weakness
RegistrationMagic is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jan 22, 2026 |
CVE-2026-24374
RegistrationMagic: Cross-site request forgery
RegistrationMagic is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Jan 17, 2026 |
CVE-2025-15403
RegistrationMagic: Privilege escalation or authentication bypass
RegistrationMagic is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Oct 08, 2025 |
CVE-2025-11204
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: SQL injection
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Apr 04, 2025 |
CVE-2025-2836
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: Cross-site scripting
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is affected by cross-site scripting. Exploitation requires at least subscriber-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Nov 09, 2024 |
CVE-2024-10508
RegistrationMagic – User Registration Plugin with Custom Registration Forms: Privilege escalation or authentication bypass
RegistrationMagic – User Registration Plugin with Custom Registration Forms is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Aug 19, 2024 |
CVE-2024-43317
RegistrationMagic: Cross-site scripting
RegistrationMagic is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.3
NVD6.1
|
| Aug 01, 2024 |
CVE-2024-39643
RegistrationMagic: Cross-site scripting
RegistrationMagic is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.8
NVD6.1
|
| Jun 04, 2024 |
CVE-2023-51544
RegistrationMagic: A security weakness
RegistrationMagic is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Jun 04, 2024 |
CVE-2023-51543
RegistrationMagic: Privilege escalation or authentication bypass
RegistrationMagic is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE5.3
NVD7.5
|
| May 03, 2024 |
CVE-2024-33947
RegistrationMagic: Cross-site scripting
RegistrationMagic is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Apr 24, 2024 |
CVE-2023-23989
RegistrationMagic: Cross-site scripting
RegistrationMagic is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.3
NVD6.5
|
| Apr 24, 2024 |
CVE-2023-23976
RegistrationMagic: A security weakness
RegistrationMagic is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Apr 11, 2024 |
CVE-2024-25935
RegistrationMagic: A security weakness
RegistrationMagic is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD9.8
|
| Apr 09, 2024 |
CVE-2024-1991
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: Privilege escalation or authentication bypass
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is affected by privilege escalation or authentication bypass. Exploitation requires at least subscriber-level access. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Mar 26, 2024 |
CVE-2024-2951
RegistrationMagic: Cross-site request forgery
RegistrationMagic is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Mar 19, 2024 |
CVE-2024-29113
RegistrationMagic: Cross-site scripting
RegistrationMagic is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Feb 01, 2024 |
CVE-2023-51509
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: Cross-site scripting
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Dec 28, 2023 |
CVE-2023-50846
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: SQL injection
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVD7.2
|
| Nov 30, 2023 |
CVE-2023-47645
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: Cross-site request forgery
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD8.8
|
| May 16, 2023 |
CVE-2023-2548
RegistrationMagic: A security weakness
RegistrationMagic is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.6
NVD7.2
|
| May 16, 2023 |
CVE-2023-2499
RegistrationMagic: Privilege escalation or authentication bypass
RegistrationMagic is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Mar 13, 2023 |
CVE-2023-25991
Custom Registration Form Builder With Submission Manager: Cross-site request forgery
Custom Registration Form Builder With Submission Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|
| Mar 12, 2020 |
CVE-2020-8436
Custom Registration Form Builder With Submission Manager: Cross-site scripting
Custom Registration Form Builder With Submission Manager is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Mar 12, 2020 |
CVE-2020-8435
Custom Registration Form Builder With Submission Manager: SQL injection
Custom Registration Form Builder With Submission Manager is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.1
NVD8.1
|
| Mar 06, 2020 |
CVE-2020-9458
Custom Registration Form Builder With Submission Manager: A security weakness
Custom Registration Form Builder With Submission Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Mar 06, 2020 |
CVE-2020-9457
Custom Registration Form Builder With Submission Manager: Privilege escalation or authentication bypass
Custom Registration Form Builder With Submission Manager is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Mar 06, 2020 |
CVE-2020-9456
Custom Registration Form Builder With Submission Manager: A security weakness
Custom Registration Form Builder With Submission Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Mar 06, 2020 |
CVE-2020-9455
Custom Registration Form Builder With Submission Manager: A security weakness
Custom Registration Form Builder With Submission Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Mar 06, 2020 |
CVE-2020-9454
Custom Registration Form Builder With Submission Manager: Cross-site request forgery
Custom Registration Form Builder With Submission Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE8.8
NVD8.8
|