CVE-2026-77794: RegistrationMagic 6.0.0.0 - 6.0.9.8 - Unauthenticated Payment Bypass via Zero Quantity
The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users to register without paying and obtain an activated account holding the role the form grants.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Sites using RegistrationMagic versions before 6.0.9.9 are exposed if they offer paid registration forms. The impact is greatest where successful registration grants an account a role with access or privileges.
What does an attacker need to exploit it?
An attacker does not need authentication or user interaction. They can supply a zero quantity multiplier during a paid registration to cause the calculated total price to be zero.
What is the practical impact of successful exploitation?
An attacker can complete a registration without paying and receive an activated account with the role assigned by the affected form. The resulting access depends on the role that form grants.
How can I tell whether my site may be affected?
Check whether RegistrationMagic is installed at a version earlier than 6.0.9.9 and whether it has paid registration forms. Review registrations for accounts created through paid forms where payment was not collected or the calculated quantity was zero.