Authentication Bypass in RegistrationMagic Plugin for WordPress
CVE-2026-9242
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 June 2026
What is CVE-2026-9242?
The RegistrationMagic plugin for WordPress contains a significant vulnerability due to improper verification of data authenticity, allowing unauthorized users to bypass authentication. An attacker can submit a forged PayPal IPN request, which does not require any authentication or nonce validation, to overwrite the user ID in a payment log entry. This unauthorized change enables attackers to authenticate as any WordPress user, including administrators, potentially leading to a full compromise of user accounts. As a result, the database can be manipulated, allowing the attacker to gain access to sensitive information and perform actions on behalf of legitimate users.
Affected Version(s)
RegistrationMagic β Custom Registration Forms, User Registration, Payment, and User Login 0 <= 6.0.8.6