Unknown Registrationmagic vulnerabilities
3 known vulnerabilities affecting unknown/registrationmagic.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2026-0929MEDIUMCVSS 4.3fixed in 6.0.7.22026-02-16
CVE-2026-0929 [MEDIUM] CWE-862 CVE-2026-0929: The RegistrationMagic WordPress plugin before 6.0.7.2 does not have proper capability checks, allow
The RegistrationMagic WordPress plugin before 6.0.7.2 does not have proper capability checks, allowing subscribers and above to create forms on the site.
cvelistv5nvd
CVE-2025-15520MEDIUMCVSS 4.3fixed in 6.0.7.22026-02-13
CVE-2025-15520 [MEDIUM] CWE-200 CVE-2025-15520: The RegistrationMagic WordPress plugin before 6.0.7.2 checks nonces but not capabilities, allowing
The RegistrationMagic WordPress plugin before 6.0.7.2 checks nonces but not capabilities, allowing for the disclosure of some sensitive data to subscribers and above.
cvelistv5nvd
CVE-2024-9390MEDIUMCVSS 4.8fixed in 6.0.2.12025-05-15
CVE-2024-9390 [MEDIUM] CWE-79 CVE-2024-9390: The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its sett
The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
cvelistv5nvd