Executive brief
RegistrationMagic is a popular WordPress plugin used to create user registration and form submission forms on websites. This vulnerability allows attackers to bypass the login system and log in as other users without knowing their passwords, potentially gaining unauthorized access to user accounts and sensitive information stored in the registration system.
Technical details
The vulnerability is a broken authentication flaw (OWASP A7) affecting RegistrationMagic versions 6.0.9.8 and below. The issue allows unauthenticated attackers to bypass the login mechanism and impersonate legitimate users without requiring valid credentials. The attack requires no prior authentication or special privileges and is exploitable over the network through the WordPress plugin interface. Successful exploitation grants attackers unauthorized access to user accounts and associated data. A patch is available in version 6.0.9.9 and later.
Affected products
- MagicFields RegistrationMagic <= 6.0.9.8
Timeline
- 2026-08-31: disclosed: CVE-2026-82225 published on NVD
- 2026-08-28: other: Vulnerability reported and advisory published by Patchstack
- 2026-08-28: patched: Patched in version 6.0.9.9