SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77790

MEDIUM · CVSS 5.5 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The RegistrationMagic plugin for WordPress, prior to version 6.0.9.4, is vulnerable due to inadequate sanitization and escaping of parameters in SQL statements, potentially allowing high-privilege users, such as administrators, to execute SQL injection attacks. This vulnerability could lead to unauthorized access to sensitive data or manipulation of the database. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk.

CVE
CVE-2026-77790
Severity
MEDIUM
CVSS
5.5
EPSS
0.21%
WordPress

Original NVD Description

The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using it in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks.