Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 29 Jan 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Metagauss
Metagauss registrationmagic Wordpress Wordpress wordpress |
|
| Vendors & Products |
Metagauss
Metagauss registrationmagic Wordpress Wordpress wordpress |
Wed, 28 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 28 Jan 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The RegistrationMagic plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.0.7.4. This is due to missing nonce verification and capability checks on the rm_set_otp AJAX action handler. This makes it possible for unauthenticated attackers to modify arbitrary plugin settings, including reCAPTCHA keys, security settings, and frontend menu titles. | |
| Title | RegistrationMagic <= 6.0.7.4 - Missing Authorization to Unauthenticated Arbitrary Settings Modification | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-01-28T14:43:48.192Z
Reserved: 2026-01-16T17:03:05.877Z
Link: CVE-2026-1054
Updated: 2026-01-28T14:43:39.103Z
Status : Awaiting Analysis
Published: 2026-01-28T08:16:03.230
Modified: 2026-01-29T16:31:35.700
Link: CVE-2026-1054
No data.
OpenCVE Enrichment
Updated: 2026-01-29T09:18:21Z