CVE-2026-77793
Received Received - Intake

RegistrationMagic Plugin Unauthenticated Free Registration Vulnerability

Vulnerability report for CVE-2026-77793, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: WPScan

Description

The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-side, allowing unauthenticated users to complete a paid registration without paying and obtain an activated account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
registrationmagic registrationmagic to 6.0.9.9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-602 The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the RegistrationMagic WordPress plugin versions before 6.0.9.9. It allows unauthenticated users to bypass payment for paid registrations by exploiting a server-side validation flaw. The plugin fails to verify the total price, enabling users to complete registration without paying while still obtaining an activated account.

Detection Guidance

Check the installed version of the RegistrationMagic plugin in your WordPress admin panel. If it is below 6.0.9.9, the system is vulnerable. No specific commands are provided in the context.

Impact Analysis

This vulnerability could allow attackers to create activated accounts without paying for paid registrations. For website owners, it may result in lost revenue, unauthorized access to premium features, and potential misuse of registration systems. Users might face compromised accounts or unauthorized access to restricted content.

Mitigation Strategies

Update the RegistrationMagic plugin to version 6.0.9.9 or later immediately to patch the vulnerability. Disable paid registrations temporarily if an update is not immediately possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77793. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart