Junglewise Threat Intelligence

CVE-2026-49764: RegistrationMagic authentication bypass in WordPress plugin

CVE-2026-49764 · Severity: critical · CVSS 9.8 · Published 2026-06-15

Technologies: Metagauss RegistrationMagic. Vendors: Metagauss.

Executive brief

RegistrationMagic, a popular WordPress plugin used for creating custom registration forms and managing user submissions, contains a critical security flaw. This vulnerability allows an unauthenticated attacker to bypass security checks and potentially gain full administrative access to the website. Such an exploit could lead to complete site takeover, data theft, or the installation of malicious software.

Technical details

RegistrationMagic (versions 6.0.8.6 and below) is vulnerable to an authentication bypass (CWE-288) via an alternate path or channel. The flaw allows an unauthenticated remote attacker to bypass standard authentication mechanisms, potentially gaining the privileges of high-level users, including administrators. The vulnerability is reportedly related to specific endpoints, including those used for legacy PayPal IPN payment flows. An attacker can exploit this over the network without any user interaction. A patch is available in version 6.0.8.7.

Affected products

  • Metagauss RegistrationMagic <= 6.0.8.6

Timeline

  • 2026-04-30: other: Reported by James Paremain
  • 2026-06-04: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date

References

Related threats