Stored Cross-Site Scripting in RegistrationMagic WordPress Plugin
CVE-2026-77792
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 2 September 2026
Badges
What is CVE-2026-77792?
The RegistrationMagic plugin for WordPress, prior to version 6.0.9.9, is vulnerable to Stored Cross-Site Scripting (XSS) due to improper escaping of registration form field values. This vulnerability permits unauthenticated attackers to inject malicious scripts that execute in the browser of high privilege users, including administrators, upon viewing the affected content in the administrative interface. This failure to sanitize user input leads to significant security implications, making it crucial for site administrators to upgrade to the patched version to mitigate potential risks.
Affected Version(s)
RegistrationMagic 0 < 6.0.9.9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.