CVE-2026-77794: RegistrationMagic 6.0.0.0 - 6.0.9.8 - Unauthenticated Payment Bypass via Zero Quantity

Published Sep 2, 2026
·
Updated

The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users to register without paying and obtain an activated account holding the role the form grants.

Affected Software

1 affected component
RegistrationMagic WordPress plugin<6.0.9.9

Event History

Sep 2, 2026
CVE Published
via MITRE·02:16 PM
Data Sourced
via MITRE·02:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Sites using RegistrationMagic versions before 6.0.9.9 are exposed if they offer paid registration forms. The impact is greatest where successful registration grants an account a role with access or privileges.

2

What does an attacker need to exploit it?

An attacker does not need authentication or user interaction. They can supply a zero quantity multiplier during a paid registration to cause the calculated total price to be zero.

3

What is the practical impact of successful exploitation?

An attacker can complete a registration without paying and receive an activated account with the role assigned by the affected form. The resulting access depends on the role that form grants.

4

How can I tell whether my site may be affected?

Check whether RegistrationMagic is installed at a version earlier than 6.0.9.9 and whether it has paid registration forms. Review registrations for accounts created through paid forms where payment was not collected or the calculated quantity was zero.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203