CVE-2026-82225
largeUnauthenticated Broken Authentication in RegistrationMagic WordPress Plugin
CVE-2026-82225 is an unauthenticated broken authentication flaw (CWE-288, authentication bypass via an alternate path) in the RegistrationMagic WordPress plugin affecting versions up to and including 6.0.9.8. A remote attacker with no credentials can send crafted requests to the plugin's authentication-related functionality and, when the required conditions align (reflected in the high attack-complexity rating), bypass the intended authentication check. Successful exploitation has a high impact on confidentiality and integrity with no availability impact, meaning an attacker can effectively gain an authenticated context or manipulate user/account state without valid credentials. Any WordPress site running RegistrationMagic 6.0.9.8 or earlier is affected. There is no known public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS places 30-day exploitation probability at roughly 0.2%, so no confirmed in-the-wild exploitation is currently known.
What to do: Update RegistrationMagic to the latest available release, i.e., any version newer than 6.0.9.8. Until patched, consider restricting the plugin's publicly reachable authentication/registration endpoints (e.g., via WAF rules) and audit user accounts — especially administrator accounts created or modified recently — for signs of unauthorized access. Site owners should verify their installed plugin version, as the flaw requires no credentials to attempt.
| RegistrationMagic WordPress plugin | <= 6.0.9.8 (all versions up to and including 6.0.9.8) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-288
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.