CVE-2026-73341: WordPress RegistrationMagic plugin <= 6.0.9.7 - PHP Object Injection vulnerability
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress RegistrationMagicto a version that resolves this vulnerability.Fixed in 6.0.9.8
Event History
Frequently Asked Questions
Which deployments are affected?
Sites using RegistrationMagic version 6.0.9.7 or earlier are identified as affected. The provided data does not specify whether any particular plugin configuration is required.
What access does an attacker need to exploit this issue?
Exploitation is unauthenticated and requires no user interaction. The listed vector indicates network-reachable exploitation with low attack complexity.
What can be done if a patch is not immediately available?
The supplied information does not identify a fixed version or any temporary mitigation. Administrators should treat installations at or below 6.0.9.7 as affected until they can verify remediation from the vendor or advisory source.