CVE-2025-15520

Severity
4.3MEDIUM
EPSS
0.0%
top 89.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 13

Description

The RegistrationMagic WordPress plugin before 6.0.7.2 checks nonces but not capabilities, allowing for the disclosure of some sensitive data to subscribers and above.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages1 packages

CVEListV5unknown/registrationmagic< 6.0.7.2

🔴Vulnerability Details

2
GHSA
GHSA-h892-rh45-x8jp: The RegistrationMagic WordPress plugin before 62026-02-13
CVEList
RegistrationMagic <= 6.0.7.2 - Subscriber+ Sensitive Data Disclosure2026-02-13

🕵️Threat Intelligence

1
Wiz
CVE-2025-15520 Impact, Exploitability, and Mitigation Steps | Wiz