← WordPress Vulnerabilities
WordPress security by component

RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login

RegistrationMagic creates custom user registration forms with fields, submissions, payments, user accounts, and login features.

RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login (registrationmagic) is a WordPress plugin with 18 published CVE records in this archive. The latest tracked vulnerability was published Sep 05, 2026; the highest published CVSS base score is 9.8.

Plugin slug: registrationmagic

CVE-2026-77826: RegistrationMagic accepts Facebook tokens issued to other applications

RegistrationMagic 5.0.1.8 through 6.0.9.8 does not verify that a Facebook access token was issued for the site's configured application. An unauthenticated attacker with a token for an existing user can log in as that user, or create and enter a new account even when WordPress registration is disabled.

PublishedSep 05, 2026
Known safe version6.0.9.9
Published vulnerabilities for registrationmagic
Safe version
Sep 05, 2026 CVE-2026-77826
RegistrationMagic accepts Facebook tokens issued to other applications
RegistrationMagic 5.0.1.8 through 6.0.9.8 does not verify that a Facebook access token was issued for the site's configured application. An unauthenticated attacker with a token for an existing user can log in as that user, or create and enter a new account even when WordPress registration is disabled.
6.0.9.9
CVE8.8
NVDPending
Sep 02, 2026 CVE-2026-77794
RegistrationMagic quantity manipulation bypasses paid registration
RegistrationMagic 6.0.0.0 through 6.0.9.8 trusts a client-supplied quantity multiplier when calculating paid-registration totals. An unauthenticated visitor can manipulate the value, complete registration without payment, and receive the role configured for that form.
6.0.9.9
CVE5.3
NVDPending
Sep 02, 2026 CVE-2026-77793
RegistrationMagic accepts unpaid registrations as activated accounts
RegistrationMagic before 6.0.9.9 does not validate a paid registration's total on the server. An unauthenticated visitor can complete the registration without paying and receive an activated WordPress account.
6.0.9.9
CVE5.3
NVDPending
Aug 26, 2026 CVE-2026-77790
RegistrationMagic permits Administrator-level SQL injection
RegistrationMagic before 6.0.9.4 inserts an insufficiently sanitized and escaped parameter into an SQL statement. A high-privilege user such as an Administrator can inject SQL into the WordPress database.
6.0.9.4
CVE5.5
NVDPending
Aug 06, 2026 CVE-2026-15208
RegistrationMagic accepts mismatched or replayed PayPal captures before 6.0.9.5
RegistrationMagic before 6.0.9.5 verifies only that a submitted PayPal capture reports COMPLETED. It does not bind the capture to the registration by checking amount, currency or payee and does not reject a reused capture. An unauthenticated attacker can use a genuine low-value capture to finalize a more expensive registration, then replay it for additional registrations. The callback endpoint or action, capture-ID parameter and verification and finalization functions are not disclosed.
6.0.9.5
CVE5.3
NVDPending
Jul 30, 2026 CVE-2026-15257
RegistrationMagic lets visitors overwrite other users' submissions
RegistrationMagic before 6.0.9.4 routes a public request with rm_slug=rm_user_form_edit_sub to RM_Front_Form_Controller::edit_sub(). Attacker-controlled form_id and submission_id values are passed to create_form_prefilled() and save_edited_submission() without authentication, ownership validation or a submission-bound nonce. Submitted field values then replace the selected submission, and update_user_profile() writes the edited profile fields to the non-administrator WordPress account identified by the submitted email address. Version 6.0.9.4 binds the edit to the authorized email, verifies the form/submission owner and a nonce, and rejects privileged user-meta keys.
6.0.9.4
CVE5.3
NVDPending
Jul 30, 2026 CVE-2026-15255
RegistrationMagic OTP cookies expose other users' submissions
RegistrationMagic before 6.0.9.4 validates the rm_secure_otp cookie against a front-user record but obtains the authorized identity separately from the attacker-controlled rm_autorized_email cookie. A visitor with a valid RegistrationMagic OTP session for one email can replace the email cookie with another identity, then request the configured front-end submissions page and select a submission_id; RM_Front_Controller::submissions() treats that cookie value as the authorized email and returns the matching user's submission details, including personal information. No WordPress account is required. Version 6.0.9.4 resolves the email from the database row bound to the OTP instead of trusting the separate email cookie.
6.0.9.4
CVE5.3
NVDPending
Feb 16, 2026 CVE-2026-0929
RegistrationMagic: A security weakness
RegistrationMagic is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Feb 13, 2026 CVE-2025-15520
RegistrationMagic: A security weakness
RegistrationMagic is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Oct 18, 2025 CVE-2017-20208
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: Code execution
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is affected by code execution. The vulnerable path is reachable without authentication. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVDPending
May 15, 2025 CVE-2024-9390
RegistrationMagic: Cross-site scripting
RegistrationMagic is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Jan 31, 2025 CVE-2025-24686
RegistrationMagic: Cross-site scripting
RegistrationMagic is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1
Dec 09, 2024 CVE-2023-49831
RegistrationMagic: A security weakness
RegistrationMagic is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5
Apr 09, 2024 CVE-2024-1990
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: SQL injection
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login is affected by SQL injection. Exploitation requires an authenticated contributor account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVDPending
Mar 07, 2022 CVE-2022-0420
RegistrationMagic: SQL injection
RegistrationMagic is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVEPending
NVD7.2
Feb 01, 2022 CVE-2021-24648
RegistrationMagic: Cross-site scripting
RegistrationMagic is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1
Jan 10, 2022 CVE-2021-24862
RegistrationMagic: SQL injection
RegistrationMagic is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVEPending
NVD7.2
Dec 14, 2021 CVE-2021-4073
RegistrationMagic: A security weakness
RegistrationMagic is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.8
NVD8.1