CVE-2026-82225: WordPress RegistrationMagic plugin <= 6.0.9.8 - Broken Authentication vulnerability
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress RegistrationMagic Pluginto a version that resolves this vulnerability.Fixed in 6.0.9.9
Event History
Frequently Asked Questions
Which installations should be treated as affected?
WordPress sites using RegistrationMagic version 6.0.9.8 or an earlier version should be treated as affected based on the stated version range.
Does exploitation require an existing account or user interaction?
No. The vulnerability is described as unauthenticated, and the vector indicates no privileges and no user interaction are required. Exploitation is network-accessible, although the attack complexity is rated high.
What impact is indicated if exploitation succeeds?
The severity vector indicates high confidentiality and integrity impact, with no availability impact indicated. The supplied data does not specify the exact actions an attacker can perform after exploiting the authentication flaw.