๐Ÿ” CVE Alert

CVE-2026-15257

MEDIUM 5.3

RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission and User Profile Modification

CVSS Score
5.3
EPSS Score
0.1%
EPSS Percentile
4th

The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing action, allowing unauthenticated attackers to overwrite other users' form submissions and the profile fields of the associated non-administrator WordPress accounts.

Vendor unknown
Product registrationmagic
Published Jul 30, 2026
Last Updated Jul 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown registrationmagic

Be the first to know when new medium vulnerabilities affecting unknown registrationmagic are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / RegistrationMagic
0 < 6.0.9.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/fe6d0f6a-c2b4-4cd1-a7d2-e3afec76ebca/

Credits

Jonatan Buskila WPScan