Junglewise Threat Intelligence

CVE-2026-12158: Metagauss RegistrationMagic CSRF privilege escalation

CVE-2026-12158 · Severity: high · CVSS 8.8 · Published 2026-07-01

Technologies: Metagauss RegistrationMagic. Vendors: Metagauss.

Executive brief

RegistrationMagic is a WordPress plugin used to create custom user registration forms and manage submissions. A security flaw allows an attacker to trick a site administrator into unknowingly performing an action, such as clicking a link, which can result in the attacker gaining full administrative control over the website. This could lead to complete site takeover, data theft, or the insertion of malicious content.

Technical details

The RegistrationMagic plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the 'process_request' function. By leveraging this vulnerability, an unauthenticated attacker can forge a request to create a malicious Chronos automation task. If a site administrator is tricked into executing the forged request (e.g., by clicking a link), the malicious task is subsequently executed via WordPress cron. This allows the attacker to escalate the privileges of an arbitrary form submitter to the administrator level, leading to full site compromise.

Affected products

  • Metagauss RegistrationMagic – User Registration Forms Plugin up to, and including, 6.0.9.1

Timeline

  • 2026-07-01: disclosed: NVD publication date

References

Related threats