CVE-2026-77793: RegistrationMagic < 6.0.9.9 - Unauthenticated Payment Bypass via Omitted Price Field
The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-side, allowing unauthenticated users to complete a paid registration without paying and obtain an activated account.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
WordPress sites using RegistrationMagic versions earlier than 6.0.9.9 that offer paid registrations are exposed. An unauthenticated visitor can target the affected registration flow.
What does an attacker need to exploit it?
The attacker does not need an existing account, authentication, or user interaction. Exploitation relies on omitting the price field during a paid registration request.
What is the impact of successful exploitation?
An attacker can complete a paid registration without making the required payment and receive an activated account. The provided severity vector indicates integrity impact only, with no stated confidentiality or availability impact.
What should be done to remediate the issue?
Update RegistrationMagic to version 6.0.9.9 or later. The affected versions are those before 6.0.9.9.