Metagauss
Metagauss Registrationmagic: vulnerabilidades y CVE
Metagauss Registrationmagic tiene 58 vulnerabilidades publicadas, 24 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE58
Últimos 12 meses24
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-77826 | Alta (8.8) | 0.41% | — | 5 sept 2026 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an… |
| CVE-2026-77794 | Media (5.3) | 0.32% | — | 2 sept 2026 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users to register without… |
| CVE-2026-77793 | Media (5.3) | 0.32% | — | 2 sept 2026 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-side, allowing unauthenticated users to complete a paid registration without paying and obtain an… |
| CVE-2026-77792 | Alta (7.5) | 0.37% | — | 2 sept 2026 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape a registration form field value before outputting it in an HTML attribute on an administrative page, allowing unauthenticated users to perform Stored… |
| CVE-2026-82225 | Alta (7.4) | 0.39% | — | 31 ago 2026 | Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions. |
| CVE-2026-77790 | Media (5.5) | 0.27% | — | 26 ago 2026 | The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using it in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks. |
| CVE-2026-15208 | Media (5.3) | 0.16% | — | 6 ago 2026 | The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, payee, or prior use against the registration it is finalising: its server-side check only confirms… |
| CVE-2026-15257 | Media (5.3) | 0.30% | — | 30 jul 2026 | The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a front-end submission-editing action, allowing unauthenticated attackers to overwrite other users' form… |
| CVE-2026-15255 | Media (5.3) | 0.32% | — | 30 jul 2026 | The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the identity being requested before returning front-end form submissions,… |
| CVE-2026-12158 | Alta (8.8) | 0.32% | — | 1 jul 2026 | The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.0.9.1. This is due to missing or incorrect nonce validation… |
| CVE-2026-9242 | Media (5.3) | 0.34% | — | 27 jun 2026 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Verification of Data Authenticity in all… |
| CVE-2026-49764 | Crítica (9.8) | 0.61% | — | 15 jun 2026 | Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions. |
| CVE-2026-32498 | Alta (7.5) | 0.39% | — | 25 mar 2026 | Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects… |
| CVE-2026-24373 | Alta (8.1) | 0.38% | — | 25 mar 2026 | Incorrect Privilege Assignment vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Privilege Escalation.This issue affects RegistrationMagic: from n/a through <=… |
| CVE-2026-32385 | Media (5.4) | 0.29% | — | 13 mar 2026 | Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects… |
| CVE-2025-14444 | Media (5.3) | 0.22% | — | 18 feb 2026 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to payment bypass due to insufficient verification of data authenticity on the… |
| CVE-2026-0929 | Media (4.3) | 0.22% | — | 16 feb 2026 | The RegistrationMagic WordPress plugin before 6.0.7.2 does not have proper capability checks, allowing subscribers and above to create forms on the site. |
| CVE-2025-15520 | Media (4.3) | 0.18% | — | 13 feb 2026 | The RegistrationMagic WordPress plugin before 6.0.7.2 checks nonces but not capabilities, allowing for the disclosure of some sensitive data to subscribers and above. |
| CVE-2026-1054 | Media (5.3) | 0.26% | — | 28 ene 2026 | The RegistrationMagic plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.0.7.4. This is due to missing nonce verification and capability checks on the rm_set_otp AJAX action… |
| CVE-2026-24374 | Media (5.4) | 0.11% | — | 22 ene 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Cross Site Request Forgery.This issue affects RegistrationMagic: from n/a… |
| CVE-2025-15403 | Crítica (9.8) | 1.7% | — | 17 ene 2026 | The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.0.7.1. This is due to the 'add_menu' function is accessible via the 'rm_user_exists' AJAX action… |
| CVE-2025-13610 | Media (6.4) | 0.18% | — | 15 dic 2025 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'RM_Forms' shortcode in all versions up… |
| CVE-2017-20208 | Crítica (9.8) | 0.71% | — | 18 oct 2025 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.7.9.3 (exclusive) via deserialization of… |
| CVE-2025-11204 | Alta (7.2) | 0.41% | — | 8 oct 2025 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 6.0.6.2 due to insufficient… |
| CVE-2024-9390 | Media (4.8) | 0.31% | — | 15 may 2025 | The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2025-2836 | Media (6.4) | 0.32% | — | 4 abr 2025 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘payment_method’ parameter in all versions up to,… |
| CVE-2025-24686 | Media (6.1) | 0.26% | — | 31 ene 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Reflected XSS.This issue… |
| CVE-2023-49831 | Alta (7.5) | 0.57% | — | 9 dic 2024 | Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects… |
| CVE-2024-10508 | Crítica (9.8) | 1.5% | — | 9 nov 2024 | The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0.2.6. This is due… |
| CVE-2024-43317 | Media (6.1) | 0.27% | — | 19 ago 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Metagauss User Registration Team RegistrationMagic allows Cross-Site Scripting (XSS).This issue affects… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.