RegistrationMagic <= 6.0.7.4 - Missing Authorization to Unauthenticated Arbitrary Settings Modification
RegistrationMagic – User Registration Forms Plugin
Minimum safe version
6.0.7.7
Update to 6.0.7.7 or later to address 59 fixable vulnerabilities
RegistrationMagic < 6.0.7.2 - Missing Authorization
CVE-2026-32498
CVE-2026-24373
CVE-2026-32385
CVE-2025-14444
CVE-2025-15520
CVE-2026-24374
CVE-2025-15403
CVE-2025-13610
CVE-2017-20208
CVE-2025-11204
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.2 - Authenticated (Admin+) Stored Cross-Site Scripting
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.4.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting
CVE-2025-24686
WordPress RegistrationMagic Plugin <= 6.0.2.6 is vulnerable to Privilege Escalation
CVE-2024-43317
CVE-2024-39643
CVE-2024-33947
CVE-2024-1990
CVE-2024-2951
CVE-2024-29113
CVE-2024-1991
CVE-2024-25935
RegistrationMagic <= 5.2.5.9 - Cross-Site Request Forgery
WordPress RegistrationMagic Plugin <= 5.2.4.1 is vulnerable to Cross Site Scripting (XSS)
WordPress RegistrationMagic Plugin <= 5.2.5.0 is vulnerable to Bypass Vulnerability
WordPress RegistrationMagic Plugin <= 5.2.5.0 is vulnerable to Bypass Vulnerability
WordPress RegistrationMagic Plugin <= 5.2.4.5 is vulnerable to SQL Injection
CVE-2023-49831
CVE-2023-47645
RegistrationMagic <= 5.2.4.1 - Reflected Cross-Site Scripting via section_id
CVE-2023-2548
CVE-2023-2499
CVE-2023-25991
CVE-2023-23989
CVE-2023-23976
RegistrationMagic - Custom Registration Forms <= 3.7.9.2 - PHP Object Injection
RegistrationMagic - Custom Registration Forms <= 3.8.0.4 - SQL Injection
RegistrationMagic - Custom Registration Forms <= 3.7.9.4 - Reflected Cross-Site Scripting
wpscan.com
RegistrationMagic - Custom Registration Forms <= 3.8.0.4 - Authenticated SQL Injection
RegistrationMagic - Custom Registration Forms <= 3.8.0.4 - Authenticated Reflected XSS
Registration Magic < 5.0.1.9 - Reflected Cross-Site Scripting
WordPress RegistrationMagic-Custom Registration Forms plugin <= 3.7.9.2 - Unauthenticated PHP Object Injection vulnerability
WordPress RegistrationMagic plugin <= 4.6.0.1 - Authenticated SQL Injection (SQLi) vulnerability
WordPress RegistrationMagic plugin <= 4.6.0.3 - Multiple Critical vulnerabilities
WordPress RegistrationMagic plugin <= 5.0.1.8 - Reflected Cross-Site Scripting (XSS) vulnerability
CVE-2020-9458
CVE-2020-9457
CVE-2020-9456
CVE-2020-9455
CVE-2020-9454
CVE-2020-8436
CVE-2020-8435
CVE-2021-4073
RegistrationMagic <= 5.0.1.5 - SQL Injection
CVE-2021-24648
CVE-2022-0420