๐Ÿ” CVE Alert

CVE-2026-15255

MEDIUM 5.3

RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission Disclosure via IDOR

CVSS Score
5.3
EPSS Score
0.1%
EPSS Percentile
4th

The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the identity being requested before returning front-end form submissions, allowing unauthenticated attackers to read other users' form submission data, including personal information.

Vendor unknown
Product registrationmagic
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown registrationmagic

Be the first to know when new medium vulnerabilities affecting unknown registrationmagic are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / RegistrationMagic
0 < 6.0.9.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/21fa84b9-afa6-49f7-abb1-c1edabda3cd8/

Credits

Jonatan Buskila WPScan