CVE-2026-15257: Unknown Registrationmagic

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing action, allowing unauthenticated attackers to overwrite other users' form submissions and the profile fields of the associated non-administrator WordPress accounts.

Affected products

  • Unknown Registrationmagic: before 6.0.9.4 (fixed in 6.0.9.4)

Published 2026-07-30. Last modified 2026-07-30.