Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
60 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.41% | — | Metagauss RegistrationmagicAI | 5/9/2026 | 8/9/2026 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token they can obtain, or to create and log into a new account even when user… | |
| Aplazada | Media (5.3) | 0.32% | — | Metagauss RegistrationmagicAI | 2/9/2026 | 3/9/2026 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users to register without paying and obtain an activated account holding the role the form grants. | |
| Aplazada | Media (5.3) | 0.32% | — | Metagauss RegistrationmagicAI | 2/9/2026 | 3/9/2026 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-side, allowing unauthenticated users to complete a paid registration without paying and obtain an activated account. | |
| Aplazada | Alta (7.5) | 0.37% | — | Metagauss RegistrationmagicAI | 2/9/2026 | 3/9/2026 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape a registration form field value before outputting it in an HTML attribute on an administrative page, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users such as admin. | |
| Aplazada | Alta (7.4) | 0.39% | — | Metagauss RegistrationmagicAI | 31/8/2026 | 1/9/2026 | Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Registrationmagic Registration MagicAI | 31/8/2026 | 1/9/2026 | Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions. | |
| Aplazada | Media (5.5) | 0.27% | — | Metagauss RegistrationmagicAI | 26/8/2026 | 3/9/2026 | The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using it in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Registrationmagic Registration MagicAI | 18/8/2026 | 20/8/2026 | Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions. | |
| Aplazada | Media (5.3) | 0.16% | — | Metagauss RegistrationmagicAI | 6/8/2026 | 26/8/2026 | The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, payee, or prior use against the registration it is finalising: its server-side check only confirms the capture status is COMPLETED. An unauthenticated attacker can therefore finalise an expensive paid… | |
| Aplazada | Media (5.3) | 0.30% | — | Metagauss RegistrationmagicAI | 30/7/2026 | 30/7/2026 | The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing action, allowing unauthenticated attackers to overwrite other users' form submissions and the profile fields of the associated non-administrator WordPress accounts. | |
| Aplazada | Media (5.3) | 0.32% | — | Metagauss RegistrationmagicAI | 30/7/2026 | 30/7/2026 | The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the identity being requested before returning front-end form submissions, allowing unauthenticated attackers to read other users' form submission data, including personal… | |
| Aplazada | Alta (8.8) | 0.32% | — | Metagauss RegistrationmagicAI | 1/7/2026 | 1/7/2026 | The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.0.9.1. This is due to missing or incorrect nonce validation on the process_request function. This makes it possible for unauthenticated attackers to escalate… | |
| Aplazada | Media (5.3) | 0.34% | — | Metagauss RegistrationmagicAI | 27/6/2026 | 29/6/2026 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Verification of Data Authenticity in all versions up to and including 6.0.8.6. This is due to the PayPal IPN `callback` handler being registered as… | |
| Aplazada | Crítica (9.8) | 0.61% | — | Metagauss RegistrationmagicAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | Metagauss RegistrationmagicAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RegistrationMagic: from n/a through <= 6.0.7.6. | |
| Aplazada | Alta (8.1) | 0.38% | — | Metagauss RegistrationmagicAI | 25/3/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Privilege Escalation.This issue affects RegistrationMagic: from n/a through <= 6.0.7.1. | |
| Aplazada | Media (5.4) | 0.29% | — | Metagauss RegistrationmagicAI | 13/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RegistrationMagic: from n/a through <= 6.0.7.6. | |
| Aplazada | Media (5.3) | 0.22% | — | Metagauss RegistrationmagicAI | 18/2/2026 | 17/6/2026 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to payment bypass due to insufficient verification of data authenticity on the 'process_paypal_sdk_payment' function in all versions up to, and including, 6.0.6.9. This is due to the plugin… | |
| Aplazada | Media (4.3) | 0.22% | — | Metagauss RegistrationmagicAI | 16/2/2026 | 17/6/2026 | The RegistrationMagic WordPress plugin before 6.0.7.2 does not have proper capability checks, allowing subscribers and above to create forms on the site. | |
| Aplazada | Media (4.3) | 0.18% | — | Metagauss RegistrationmagicAI | 13/2/2026 | 17/6/2026 | The RegistrationMagic WordPress plugin before 6.0.7.2 checks nonces but not capabilities, allowing for the disclosure of some sensitive data to subscribers and above. | |
| Aplazada | Media (5.3) | 0.26% | — | Metagauss RegistrationmagicAI | 28/1/2026 | 17/6/2026 | The RegistrationMagic plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.0.7.4. This is due to missing nonce verification and capability checks on the rm_set_otp AJAX action handler. This makes it possible for unauthenticated attackers to modify arbitrary plugin settings,… | |
| Aplazada | Media (5.4) | 0.11% | — | Metagauss RegistrationmagicAI | 22/1/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Cross Site Request Forgery.This issue affects RegistrationMagic: from n/a through <= 6.0.6.9. | |
| Aplazada | Crítica (9.8) | 1.7% | — | Metagauss RegistrationmagicAI | 17/1/2026 | 17/6/2026 | The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.0.7.1. This is due to the 'add_menu' function is accessible via the 'rm_user_exists' AJAX action and allows arbitrary updates to the 'admin_order' setting. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.4) | 0.18% | — | Metagauss RegistrationmagicAI | 15/12/2025 | 17/6/2026 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'RM_Forms' shortcode in all versions up to, and including, 6.0.6.7 due to insufficient input sanitization and output escaping on the 'theme'… | |
| Analizada | Crítica (9.8) | 0.71% | — | Metagauss Registrationmagic | 18/10/2025 | 17/6/2026 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.7.9.3 (exclusive) via deserialization of untrusted input from the is_expired_by_date() function. This makes it possible for unauthenticated… |