CVE-2026-15257: RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission and User Profile Modification
The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing action, allowing unauthenticated attackers to overwrite other users' form submissions and the profile fields of the associated non-administrator WordPress accounts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15257?
CVE-2026-15257 has a medium severity score of 5.3.
How do I fix CVE-2026-15257?
To fix CVE-2026-15257, update the RegistrationMagic WordPress plugin to version 6.0.9.4 or later.
What is the impact of CVE-2026-15257?
CVE-2026-15257 allows unauthenticated attackers to overwrite other users' form submissions and profile fields.
Which software is affected by CVE-2026-15257?
CVE-2026-15257 affects versions of the RegistrationMagic WordPress plugin before 6.0.9.4.
What type of vulnerability is CVE-2026-15257?
CVE-2026-15257 is an unauthenticated form submission and user profile modification vulnerability.