CyberRota Analysis
AI-GeneratedThe RegistrationMagic plugin for WordPress prior to version 6.0.9.4 is vulnerable due to inadequate validation of one-time passwords stored in cookies, enabling unauthenticated attackers to access and read sensitive form submission data from other users. This vulnerability poses a risk to user privacy and data integrity, making it critical for WordPress site administrators using this plugin to prioritize updates to mitigate potential data breaches. Organizations handling personal information should take immediate action to secure their installations against this threat.
Original NVD Description
The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the identity being requested before returning front-end form submissions, allowing unauthenticated attackers to read other users' form submission data, including personal information.