CVE-2026-15255: RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission Disclosure via IDOR
The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the identity being requested before returning front-end form submissions, allowing unauthenticated attackers to read other users' form submission data, including personal information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15255?
The severity of CVE-2026-15255 is medium with a score of 5.3.
How do I fix CVE-2026-15255?
To fix CVE-2026-15255, update the RegistrationMagic WordPress plugin to version 6.0.9.4 or later.
What does CVE-2026-15255 exploit?
CVE-2026-15255 exploits a vulnerability in the RegistrationMagic plugin that allows unauthenticated users to access other users' form submission data.
What is the impact of CVE-2026-15255?
The impact of CVE-2026-15255 includes unauthorized disclosure of sensitive user data through improper validation of one-time passwords.
What versions of the RegistrationMagic plugin are affected by CVE-2026-15255?
The affected versions of the RegistrationMagic plugin are those prior to 6.0.9.4.