CVE-2026-15257: CWE-639 Authorization Bypass Through User-Controlled Key in RegistrationMagic
The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing action, allowing unauthenticated attackers to overwrite other users' form submissions and the profile fields of the associated non-administrator WordPress accounts.
AI Analysis
Technical Summary
The RegistrationMagic WordPress plugin versions prior to 6.0.9.4 do not perform necessary authorization, ownership, or nonce verification on a front-end submission-editing feature. This lack of checks enables unauthenticated attackers to modify form submissions and profile data belonging to other users who are non-administrators, effectively bypassing authorization controls. The vulnerability is categorized under CWE-639 (Authorization Bypass Through User-Controlled Key). No CVSS score or patch information is currently available.
Potential Impact
Unauthenticated attackers can overwrite form submissions and profile fields of non-administrator WordPress accounts, potentially leading to unauthorized data modification and integrity issues within the affected WordPress site. Administrative accounts are not indicated as affected. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the vulnerable functionality where possible and monitor for suspicious activity related to form submission edits. Avoid exposing the affected plugin's front-end editing features to unauthenticated users.
CVE-2026-15257: CWE-639 Authorization Bypass Through User-Controlled Key in RegistrationMagic
Description
The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing action, allowing unauthenticated attackers to overwrite other users' form submissions and the profile fields of the associated non-administrator WordPress accounts.
CVSS v3.1
Score 5.3medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The RegistrationMagic WordPress plugin versions prior to 6.0.9.4 do not perform necessary authorization, ownership, or nonce verification on a front-end submission-editing feature. This lack of checks enables unauthenticated attackers to modify form submissions and profile data belonging to other users who are non-administrators, effectively bypassing authorization controls. The vulnerability is categorized under CWE-639 (Authorization Bypass Through User-Controlled Key). No CVSS score or patch information is currently available.
Potential Impact
Unauthenticated attackers can overwrite form submissions and profile fields of non-administrator WordPress accounts, potentially leading to unauthorized data modification and integrity issues within the affected WordPress site. Administrative accounts are not indicated as affected. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the vulnerable functionality where possible and monitor for suspicious activity related to form submission edits. Avoid exposing the affected plugin's front-end editing features to unauthenticated users.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-09T13:03:43.047Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6aee0a9c2644c7f8a7ef9f
Added to database: 07/30/2026, 06:24:10 UTC
Last enriched: 07/30/2026, 06:40:12 UTC
Last updated: 07/31/2026, 00:16:45 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.