PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77790 RegistrationMagic CVE debrief

The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using it in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks. This vulnerability has a CVSS score of 5.5 and is considered medium severity. Users of the RegistrationMagic WordPress plugin, particularly those with high-privilege access, should verify their plugin version and take necessary actions to prevent exploitation. The CVE record was published on 2026-08-26T06:16:29.910Z and has not been modified since then.

Vendor
RegistrationMagic
Product
RegistrationMagic
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-26
Original CVE updated
2026-09-03
Advisory published
2026-08-26
Advisory updated
2026-09-03

Who should care

Users of the RegistrationMagic WordPress plugin, particularly those with high-privilege access, should verify their plugin version and take necessary actions to prevent exploitation. This includes administrators, security teams, and IT personnel responsible for managing WordPress sites that use the RegistrationMagic plugin. Additionally, security teams and vulnerability management teams should review the CVE record and assess their exposure to this vulnerability. Operators of WordPress sites that use the RegistrationMagic plugin should also review their site's logs and monitoring data for potential exploitation attempts. Those responsible for patch management and software updates should prioritize updating the RegistrationMagic plugin to version 6.0.9.4 or later. Furthermore, defenders should verify affected versions, review vendor remediation guidance, and assess their exposure to potential SQL injection attacks. They should also monitor plugin usage and logs for potential SQL injection attacks and restrict access to the plugin's SQL interface to prevent exploitation by high-privilege users. Lastly, security teams should consider implementing compensating controls for exposed systems while remediation is scheduled and verified, and check relevant monitoring, detection, and logs for exposed assets that need extra review. This may involve reviewing current security controls, such as firewalls and intrusion detection systems, to ensure they are properly configured to detect and prevent SQL injection attacks. By taking these steps, defenders can help prevent exploitation of this vulnerability and reduce the risk of SQL injection attacks on their WordPress sites. In addition, defenders may want to consider reviewing their asset inventory to ensure that all affected systems are accounted for and prioritized for remediation. They may also want to review their change management processes to ensure that updates to the RegistrationMagic plugin are properly tested and validated before deployment. Overall, a thorough review of the affected systems, security controls, and change management processes is necessary to ensure that the vulnerability is properly mitigated. This 3

Technical summary

The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using it in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks. This vulnerability has a CVSS score of 5.5 and is considered medium severity. The plugin is used for user registration and management on WordPress sites, and the vulnerability could be exploited by high-privilege users with access to the plugin's SQL interface.

Defensive priority

Medium priority given the CVSS score of 5.5 and the potential for SQL injection attacks.

Recommended defensive actions

  • Verify the version of the RegistrationMagic WordPress plugin and update to 6.0.9.4 or later if necessary.
  • Restrict access to the plugin's SQL interface to prevent exploitation by high-privilege users.
  • Monitor plugin usage and logs for potential SQL injection attacks.

Evidence notes

The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using it in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks. Evidence is limited; verifying affected versions and vendor remediation is recommended.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-77790 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-77790

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-77790 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77790

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.