CVE-2026-15255: Unknown Registrationmagic
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the identity being requested before returning front-end form submissions, allowing unauthenticated attackers to read other users' form submission data, including personal information.
Affected products
- Unknown Registrationmagic: before 6.0.9.4 (fixed in 6.0.9.4)
Published 2026-07-30. Last modified 2026-07-30.