PatchSiren

RegistrationMagic CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM RegistrationMagic CVE published 2026-09-02

CVE-2026-77794

The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users to register without paying and obtain an activated account holding the role the form grants. This vulnerability affects WordPress installations using the RegistrationMagic plugin, potentially leading to unautho [truncated]

MEDIUM RegistrationMagic CVE published 2026-09-02

CVE-2026-77793

The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-side, allowing unauthenticated users to complete a paid registration without paying and obtain an activated account. This vulnerability affects WordPress installations using the RegistrationMagic plugin. Defenders should assess exposure and verify the plugin version to ensure it is updated [truncated]

HIGH RegistrationMagic CVE published 2026-09-02

CVE-2026-77792

The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape a registration form field value before outputting it in an HTML attribute on an administrative page, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users such as admin. This vulnerability has a HIGH CVSS score of 7.5, indicating a high severity level. The CVE record was published on [truncated]

MEDIUM RegistrationMagic CVE published 2026-08-26

CVE-2026-77790

The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using it in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks. This vulnerability has a CVSS score of 5.5 and is considered medium severity. Users of the RegistrationMagic WordPress plugin, particularly those with high-privilege access, should verify th [truncated]

MEDIUM RegistrationMagic CVE published 2026-08-06

CVE-2026-15208

The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, payee, or prior use against the registration it is finalising: its server-side check only confirms the capture status is COMPLETED. An unauthenticated attacker can therefore finalise an expensive paid registration with any genuinely-completed low-value capture, and replay a single capture [truncated]