CVE-2026-82221
largeUnauthenticated Cross-Site Scripting (XSS) in RegistrationMagic WordPress Plugin
RegistrationMagic, a WordPress registration-form plugin, contains an unauthenticated cross-site scripting (CWE-79) flaw in all versions up to and including 6.0.9.8. Because the issue requires no privileges and low complexity, an attacker can trigger it via a crafted request or link, but the CVSS vector (UI:R) indicates a victim must interact with the malicious content for the script to execute. If successful, arbitrary JavaScript runs in the victim's browser in the context of the affected site, which can lead to session/cookie theft, unwanted actions on behalf of the user, or redirects. Any WordPress site running RegistrationMagic 6.0.9.8 or earlier is affected, including visitors and admins whose browsers render the injected script. As of now there is no public proof of concept, no CISA KEV entry, and EPSS assigns only a 0.1% probability of exploitation within 30 days, so no in-the-wild exploitation is known.
What to do: Update RegistrationMagic to the latest release available above version 6.0.9.8 and verify the installed version in the WordPress plugin list. Until patched, avoid clicking unsolicited links pointing to the affected site and consider having administrators review access logs for suspicious unauthenticated requests. Given no known PoC or exploitation, prioritize this as routine patching rather than an emergency.
| RegistrationMagic (WordPress plugin) | <= 6.0.9.8 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.