Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
Threat Entry
Updated 2026-04-15
CVE-2026-1054 - RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Plugin
The RegistrationMagic plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.0.7.4. This is due to missing nonce verification and capability checks on the rm_set_otp AJAX action handler. This makes it possible for unauthenticated attackers to modify arbitrary plugin settings, including reCAPTCHA keys, security settings, and frontend menu titles.
PLUGIN
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login
CVE-2026-1054
Risk Score
