CVE-2026-0929

Severity
4.3MEDIUM
EPSS
0.0%
top 98.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 16

Description

The RegistrationMagic WordPress plugin before 6.0.7.2 does not have proper capability checks, allowing subscribers and above to create forms on the site.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages1 packages

CVEListV5unknown/registrationmagic< 6.0.7.2

🔴Vulnerability Details

2
CVEList
RegistrationMagic < 6.0.7.2 - Subscriber+ Form Creation2026-02-16
GHSA
GHSA-5fpg-jg99-g97m: The RegistrationMagic WordPress plugin before 62026-02-16

🕵️Threat Intelligence

1
Wiz
CVE-2026-0929 Impact, Exploitability, and Mitigation Steps | Wiz