CVE-2026-15208
Received Received - Intake

RegistrationMagic WordPress Plugin PayPal Capture Validation Bypass

Vulnerability report for CVE-2026-15208, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: WPScan

Description

The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, payee, or prior use against the registration it is finalising: its server-side check only confirms the capture status is COMPLETED. An unauthenticated attacker can therefore finalise an expensive paid registration with any genuinely-completed low-value capture, and replay a single capture across unlimited registrations because captures are not de-duplicated.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
registrationmagic registrationmagic to 6.0.9.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the RegistrationMagic WordPress plugin before version 6.0.9.5. It fails to verify key details of PayPal payments during registration finalization. The plugin only checks if a payment capture status is COMPLETED but does not validate the amount, currency, payee, or whether the capture was used before. This allows attackers to finalize expensive registrations using low-value payments and reuse the same payment for multiple registrations.

Detection Guidance

To detect this vulnerability, inspect WordPress sites using the RegistrationMagic plugin versions before 6.0.9.5. Check for registrations finalized with mismatched PayPal capture amounts, currencies, or payees. Review server logs for PayPal capture replay attempts across multiple registrations.

Impact Analysis

If you use the vulnerable plugin, an attacker could register for expensive events or services without paying the full amount. Your organization might lose revenue as registrations are finalized with incorrect payments. Additionally, sensitive user data collected during registration could be exposed if the plugin's integrity is compromised.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA if it results in unauthorized access to personal or health data during registration. GDPR requires data protection by design, and HIPAA mandates secure handling of health information. The flaw may violate these regulations if user data is compromised due to improper payment verification.

Mitigation Strategies

Update the RegistrationMagic WordPress plugin to version 6.0.9.5 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15208. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart