ZeroHour

CVE-2026-82221

large

Unauthenticated Cross-Site Scripting (XSS) in RegistrationMagic WordPress Plugin

CVSS 3.1
7.1 high
EPSS
<1%p4
Published
()
Modified
AI analysis

RegistrationMagic, a WordPress registration-form plugin, contains an unauthenticated cross-site scripting (CWE-79) flaw in all versions up to and including 6.0.9.8. Because the issue requires no privileges and low complexity, an attacker can trigger it via a crafted request or link, but the CVSS vector (UI:R) indicates a victim must interact with the malicious content for the script to execute. If successful, arbitrary JavaScript runs in the victim's browser in the context of the affected site, which can lead to session/cookie theft, unwanted actions on behalf of the user, or redirects. Any WordPress site running RegistrationMagic 6.0.9.8 or earlier is affected, including visitors and admins whose browsers render the injected script. As of now there is no public proof of concept, no CISA KEV entry, and EPSS assigns only a 0.1% probability of exploitation within 30 days, so no in-the-wild exploitation is known.

What to do: Update RegistrationMagic to the latest release available above version 6.0.9.8 and verify the installed version in the WordPress plugin list. Until patched, avoid clicking unsolicited links pointing to the affected site and consider having administrators review access logs for suspicious unauthenticated requests. Given no known PoC or exploitation, prioritize this as routine patching rather than an emergency.

Affected
RegistrationMagic (WordPress plugin)<= 6.0.9.8
Estimated exposure
largeon the order of 10,000–20,000 active WordPress sites (plugin directory lists 10,000+ active installs) — Estimate is based on the plugin's published WordPress.org active-install count of 10,000+, which bounds the population of potentially affected sites.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.