Executive brief
RegistrationMagic, a popular WordPress plugin used for creating custom registration forms and managing user submissions, contains a critical security flaw. This vulnerability allows an unauthenticated attacker to bypass security checks and potentially gain full administrative access to the website. Such an exploit could lead to complete site takeover, data theft, or the installation of malicious software.
Technical details
RegistrationMagic (versions 6.0.8.6 and below) is vulnerable to an authentication bypass (CWE-288) via an alternate path or channel. The flaw allows an unauthenticated remote attacker to bypass standard authentication mechanisms, potentially gaining the privileges of high-level users, including administrators. The vulnerability is reportedly related to specific endpoints, including those used for legacy PayPal IPN payment flows. An attacker can exploit this over the network without any user interaction. A patch is available in version 6.0.8.7.
Affected products
- Metagauss RegistrationMagic <= 6.0.8.6
Timeline
- 2026-04-30: other: Reported by James Paremain
- 2026-06-04: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date