Executive brief
RegistrationMagic is a WordPress plugin used to create custom registration forms and manage user submissions. A security flaw allows unauthorized individuals to bypass security checks and view private form data submitted by other users. This could lead to the exposure of sensitive personal information, such as names, email addresses, and phone numbers, collected through the website's forms.
Technical details
The vulnerability is an Insecure Direct Object Reference (IDOR) in the front-end submission handling of the RegistrationMagic plugin. The root cause is a failure to properly validate that a one-time password (OTP) provided in a cookie matches the identity (email) being requested. An unauthenticated attacker can generate a valid OTP for their own email address and then use that OTP in conjunction with a victim's email address in the 'rm_autorized_email' cookie to access the victim's form submissions. This allows for the disclosure of PII collected via [RM_Front_Submissions] and [RM_Login] shortcodes. The issue is fixed in version 6.0.9.4.
Affected products
- Metagauss RegistrationMagic (custom-registration-form-builder-with-submission-manager) < 6.0.9.4
Timeline
- 2026-07-10: disclosed: Initial public disclosure by WPScan
- 2026-07-30: advisory: CVE published to NVD
- 2026-07-30: patched: Fixed in version 6.0.9.4