The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing action, allowing unauthenticated attackers to overwrite other users' form submissions and the profile fields of the associated non-administrator WordPress accounts.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 30 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-639 | |
| Metrics |
cvssV3_1
|
Thu, 30 Jul 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Registrationmagic
Registrationmagic registrationmagic Wordpress Wordpress wordpress |
|
| Vendors & Products |
Registrationmagic
Registrationmagic registrationmagic Wordpress Wordpress wordpress |
Thu, 30 Jul 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing action, allowing unauthenticated attackers to overwrite other users' form submissions and the profile fields of the associated non-administrator WordPress accounts. | |
| Title | RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission and User Profile Modification | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-07-30T15:00:10.130Z
Reserved: 2026-07-09T13:03:43.047Z
Link: CVE-2026-15257
Updated: 2026-07-30T14:59:15.839Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T08:15:04Z
Weaknesses