CVE-2025-15520: Unknown Registrationmagic
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The RegistrationMagic WordPress plugin before 6.0.7.2 checks nonces but not capabilities, allowing for the disclosure of some sensitive data to subscribers and above.
Affected products
- Unknown Registrationmagic: before 6.0.7.2 (fixed in 6.0.7.2)
Published 2026-02-13. Last modified 2026-06-17.