SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77794

MEDIUM · CVSS 5.3 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The RegistrationMagic plugin for WordPress prior to version 6.0.9.9 is vulnerable due to insufficient validation of client-supplied quantity multipliers, enabling unauthenticated users to bypass payment requirements and gain unauthorized access to accounts with elevated roles. This flaw poses a risk of account abuse and potential exploitation of user privileges. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of unauthorized registrations.

CVE
CVE-2026-77794
Severity
MEDIUM
CVSS
5.3
EPSS
0.19%
WordPress

Original NVD Description

The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users to register without paying and obtain an activated account holding the role the form grants.