PatchSiren cyber security CVE debrief
CVE-2026-77790 RegistrationMagic CVE debrief
The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using it in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks. This vulnerability has a CVSS score of 5.5 and is considered medium severity. Users of the RegistrationMagic WordPress plugin, particularly those with high-privilege access, should verify their plugin version and take necessary actions to prevent exploitation. The CVE record was published on 2026-08-26T06:16:29.910Z and has not been modified since then.
- Vendor
- RegistrationMagic
- Product
- RegistrationMagic
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-26
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-08-26
- Advisory updated
- 2026-09-03
Who should care
Users of the RegistrationMagic WordPress plugin, particularly those with high-privilege access, should verify their plugin version and take necessary actions to prevent exploitation. This includes administrators, security teams, and IT personnel responsible for managing WordPress sites that use the RegistrationMagic plugin. Additionally, security teams and vulnerability management teams should review the CVE record and assess their exposure to this vulnerability. Operators of WordPress sites that use the RegistrationMagic plugin should also review their site's logs and monitoring data for potential exploitation attempts. Those responsible for patch management and software updates should prioritize updating the RegistrationMagic plugin to version 6.0.9.4 or later. Furthermore, defenders should verify affected versions, review vendor remediation guidance, and assess their exposure to potential SQL injection attacks. They should also monitor plugin usage and logs for potential SQL injection attacks and restrict access to the plugin's SQL interface to prevent exploitation by high-privilege users. Lastly, security teams should consider implementing compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review. This may involve reviewing current security controls, such as firewalls and intrusion detection systems, to ensure they are properly configured to detect and prevent SQL injection attacks. By taking these steps, defenders can help prevent exploitation of this vulnerability and reduce the risk of SQL injection attacks on their WordPress sites. In addition, defenders may want to consider reviewing their asset inventory to ensure that all affected systems are accounted for and prioritized for remediation. They may also want to review their change management processes to ensure that updates to the RegistrationMagic plugin are properly tested and validated before deployment. Overall, a thorough review of the affected systems, security controls, and change management processes is necessary to ensure that the vulnerability is properly mitigated. This 3
Technical summary
The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using it in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks. This vulnerability has a CVSS score of 5.5 and is considered medium severity. The plugin is used for user registration and management on WordPress sites, and the vulnerability could be exploited by high-privilege users with access to the plugin's SQL interface.
Defensive priority
Medium priority given the CVSS score of 5.5 and the potential for SQL injection attacks.
Recommended defensive actions
- Verify the version of the RegistrationMagic WordPress plugin and update to 6.0.9.4 or later if necessary.
- Restrict access to the plugin's SQL interface to prevent exploitation by high-privilege users.
- Monitor plugin usage and logs for potential SQL injection attacks.
Evidence notes
The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using it in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks. Evidence is limited; verifying affected versions and vendor remediation is recommended.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-77790 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-77790
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-77790 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77790
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/42c48c95-1384-4414-9236-64f44bea9027/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.