CVE-2026-82221: WordPress RegistrationMagic plugin <= 6.0.9.8 - Cross Site Scripting (XSS) vulnerability
Published Aug 31, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions.
Affected Software
1 affected component
WordPress RegistrationMagic plugin<=6.0.9.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/RegistrationMagicto a version that resolves this vulnerability.Fixed in 6.0.9.9
Event History
Aug 31, 2026
CVE Published
via MITRE·08:30 PM
Data Sourced
via MITRE·08:30 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or plugin-specific privileges. Exploitation still requires user interaction, as indicated by the UI:R vector.
2
What is the potential impact if exploitation succeeds?
The supplied severity vector indicates low confidentiality, integrity, and availability impact, with scope changed. The issue is rated high with a CVSS score of 7.1.
3
Which plugin versions are affected?
RegistrationMagic versions 6.0.9.8 and earlier are affected. The provided data does not identify a fixed version.