ZeroHour

CVE-2026-82225

large

Unauthenticated Broken Authentication in RegistrationMagic WordPress Plugin

CVSS 3.1
7.4 high
EPSS
<1%p15
Published
()
Modified
AI analysis

CVE-2026-82225 is an unauthenticated broken authentication flaw (CWE-288, authentication bypass via an alternate path) in the RegistrationMagic WordPress plugin affecting versions up to and including 6.0.9.8. A remote attacker with no credentials can send crafted requests to the plugin's authentication-related functionality and, when the required conditions align (reflected in the high attack-complexity rating), bypass the intended authentication check. Successful exploitation has a high impact on confidentiality and integrity with no availability impact, meaning an attacker can effectively gain an authenticated context or manipulate user/account state without valid credentials. Any WordPress site running RegistrationMagic 6.0.9.8 or earlier is affected. There is no known public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS places 30-day exploitation probability at roughly 0.2%, so no confirmed in-the-wild exploitation is currently known.

What to do: Update RegistrationMagic to the latest available release, i.e., any version newer than 6.0.9.8. Until patched, consider restricting the plugin's publicly reachable authentication/registration endpoints (e.g., via WAF rules) and audit user accounts — especially administrator accounts created or modified recently — for signs of unauthorized access. Site owners should verify their installed plugin version, as the flaw requires no credentials to attempt.

Affected
RegistrationMagic WordPress plugin<= 6.0.9.8 (all versions up to and including 6.0.9.8)
Estimated exposure
large≈20,000–30,000 WordPress sites (estimate based on the plugin's active-install base on WordPress.org) — Estimated from the publicly listed WordPress.org active-install count for RegistrationMagic, which places the plugin in the tens of thousands of deployed sites; the exact current count is not in the source data.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.

Ecosystems
WordPress
Weakness
CWE-288
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.