CyberRota Analysis
AI-GeneratedThe RegistrationMagic plugin for WordPress prior to version 6.0.9.9 is vulnerable due to insufficient validation of client-supplied quantity multipliers, enabling unauthenticated users to bypass payment requirements and gain unauthorized access to accounts with elevated roles. This flaw poses a risk of account abuse and potential exploitation of user privileges. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of unauthorized registrations.
Original NVD Description
The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users to register without paying and obtain an activated account holding the role the form grants.