Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total9
Critical3
High2
Medium4
Reset
Showing 1-9 of 9 records
Threat Entry Updated 2026-02-18

CVE-2025-14444 - Custom Registration Form Builder With Submission Manager Plugin

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to payment bypass due to insufficient verification of data authenticity on the 'process_paypal_sdk_payment' function in all versions up to, and including, 6.0.6.9. This is due to the plugin trusting client-supplied values for payment verification without validating that the payment actually went through PayPal. This makes it possible for unauthenticated attackers to bypass paid registration by manipulating payment status and activating their account without completing a real PayPal payment.

PLUGIN Custom Registration Form Builder With Submission Manager

CVE-2025-14444

MEDIUM CVSS 5.3 2026-02-18
Threat Entry Updated 2026-04-15

CVE-2026-1054 - Custom Registration Form Builder With Submission Manager Plugin

The RegistrationMagic plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.0.7.4. This is due to missing nonce verification and capability checks on the rm_set_otp AJAX action handler. This makes it possible for unauthenticated attackers to modify arbitrary plugin settings, including reCAPTCHA keys, security settings, and frontend menu titles.

PLUGIN Custom Registration Form Builder With Submission Manager

CVE-2026-1054

MEDIUM CVSS 5.3 2026-01-28
Threat Entry Updated 2026-01-26

CVE-2025-15403 - Custom Registration Form Builder With Submission Manager Plugin

The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.0.7.1. This is due to the 'add_menu' function is accessible via the 'rm_user_exists' AJAX action and allows arbitrary updates to the 'admin_order' setting. This makes it possible for unauthenticated attackers to injecting an empty slug into the order parameter, and manipulate the plugin's menu generation logic, and when the admin menu is subsequently built, the plugin adds 'manage_options' capability for the target role. Note: The vulnerability can only be exploited unauthenticated, but further…

PLUGIN Custom Registration Form Builder With Submission Manager

CVE-2025-15403

CRITICAL CVSS 9.8 2026-01-17
Threat Entry Updated 2025-10-08

CVE-2025-11204 - Custom Registration Form Builder With Submission Manager Plugin

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 6.0.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. An unauthenticated attacker could utilize an injected Cross-Site Scripting via user-agent…

PLUGIN Custom Registration Form Builder With Submission Manager

CVE-2025-11204

HIGH CVSS 7.2 2025-10-08
Threat Entry Updated 2025-04-07

CVE-2025-2836 - Custom Registration Form Builder With Submission Manager Plugin

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘payment_method’ parameter in all versions up to, and including, 6.0.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Custom Registration Form Builder With Submission Manager

CVE-2025-2836

MEDIUM CVSS 6.4 2025-04-04
Threat Entry Updated 2025-01-29

CVE-2024-10508 - Custom Registration Form Builder With Submission Manager Plugin

The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0.2.6. This is due to the plugin not properly validating the password reset token prior to updating a user's password. This makes it possible for unauthenticated attackers to reset the password of arbitrary users, including administrators, and gain access to these accounts.

PLUGIN Custom Registration Form Builder With Submission Manager

CVE-2024-10508

CRITICAL CVSS 9.8 2024-11-09
Threat Entry Updated 2025-01-31

CVE-2024-1991 - Custom Registration Form Builder With Submission Manager Plugin

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the update_users_role() function in all versions up to, and including, 5.3.0.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to escalate their privileges to that of an administrator

PLUGIN Custom Registration Form Builder With Submission Manager

CVE-2024-1991

HIGH CVSS 8.8 2024-04-09
Threat Entry Updated 2024-11-21

CVE-2023-2499 - Custom Registration Form Builder With Submission Manager Plugin

The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.1.0. This is due to insufficient verification on the user being supplied during a Google social login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.

PLUGIN Custom Registration Form Builder With Submission Manager

CVE-2023-2499

CRITICAL CVSS 9.8 2023-05-16
Threat Entry Updated 2024-11-21

CVE-2023-2548 - Custom Registration Form Builder With Submission Manager Plugin

The RegistrationMagic plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 5.2.0.5. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers, with administrator-level permissions and above, to change user passwords and potentially take over super-administrator accounts in multisite setup.

PLUGIN Custom Registration Form Builder With Submission Manager

CVE-2023-2548

MEDIUM CVSS 6.6 2023-05-16
Scroll to top