PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77794 RegistrationMagic CVE debrief

The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users to register without paying and obtain an activated account holding the role the form grants. This vulnerability affects administrators and users of the RegistrationMagic WordPress plugin, as well as security teams responsible for monitoring and protecting against potential exploitation attempts. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Limited information is available regarding the specific technical details of the vulnerability.

Vendor
RegistrationMagic
Product
RegistrationMagic
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-02
Original CVE updated
2026-09-03
Advisory published
2026-09-02
Advisory updated
2026-09-03

Who should care

Administrators and users of the RegistrationMagic WordPress plugin, as well as security teams responsible for monitoring and protecting against potential exploitation attempts, should be aware of this vulnerability and take necessary defensive actions.

Technical summary

The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration. This allows unauthenticated users to register without paying and obtain an activated account holding the role the form grants. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. The WPScan vulnerability reference explicitly names the RegistrationMagic WordPress plugin as the affected component. Administrators and users of the RegistrationMagic WordPress plugin should be aware of this vulnerability and take necessary defensive actions to prevent exploitation attempts and unauthorized account creation. The vulnerability allows unauthenticated users to register without paying and obtain an activated account holding the role the form grants, which can lead to potential security risks if not properly addressed. It is essential to apply the vendor-provided patch to the RegistrationMagic WordPress plugin, upgrading to version 6.0.9.9 or later, and implement additional security measures to prevent exploitation attempts and protect against potential security risks. The RegistrationMagic plugin configuration should be reviewed to ensure that all instances are updated and properly secured. Limited information is available regarding the specific technical details of the vulnerability, and further review is necessary to determine the full extent of the vulnerability and potential impact. The CVE record was published on 2026-09-02T15:17:39.673Z and has not been modified since then. The NVD entry is currently Deferred. Evidence of the vulnerability includes the WPScan vulnerability reference, which explicitly names the RegistrationMagic WordPress plugin as the affected component. The official CVE Program record and NVD detail page provide additional information on the vulnerability, including its CVSS score and severity classification. The source reference providing additional vulnerability details should be reviewed to ensure that all necessary information is gathered to properly address the vulnerability. The vulnerability should be monitored, and additional authentication and Web-

Defensive priority

Medium-priority defensive actions are recommended due to the unauthenticated nature of the vulnerability and potential for unauthorized account creation.

Recommended defensive actions

  • Apply the vendor-provided patch to the RegistrationMagic WordPress plugin, upgrading to version 6.0.9.9 or later.
  • Implement Web Application Firewall (WAF) rules to detect and prevent exploitation attempts.
  • Monitor for suspicious registration activity and implement additional authentication mechanisms for registration forms.
  • Conduct a thorough review of the RegistrationMagic plugin configuration and ensure that all instances are updated and properly secured.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The WPScan vulnerability reference explicitly names the RegistrationMagic WordPress plugin as the affected component. Limited information is available regarding the specific technical details of the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-77794 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-77794

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-77794 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77794

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.