CVE-2026-15255: Unknown Registrationmagic

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the identity being requested before returning front-end form submissions, allowing unauthenticated attackers to read other users' form submission data, including personal information.

Affected products

  • Unknown Registrationmagic: before 6.0.9.4 (fixed in 6.0.9.4)

Published 2026-07-30. Last modified 2026-07-30.