Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High1
Medium1
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2026-07-01

CVE-2026-12158 - RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Plugin

The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.0.9.1. This is due to missing or incorrect nonce validation on the process_request function. This makes it possible for unauthenticated attackers to escalate the privileges of an arbitrary form submitter to administrator by creating a malicious Chronos automation task that is executed via WordPress cron via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login

CVE-2026-12158

HIGH CVSS 8.8 2026-07-01
Threat Entry Updated 2026-06-17

CVE-2026-1054 - RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Plugin

The RegistrationMagic plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.0.7.4. This is due to missing nonce verification and capability checks on the rm_set_otp AJAX action handler. This makes it possible for unauthenticated attackers to modify arbitrary plugin settings, including reCAPTCHA keys, security settings, and frontend menu titles.

PLUGIN RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login

CVE-2026-1054

MEDIUM CVSS 5.3 2026-01-28
Scroll to top