Description
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
Published: 2026-08-18
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WordPress RegistrationMagic versions up to 6.0.9.7 are vulnerable to unauthenticated PHP Object Injection. The flaw allows an attacker to supply crafted payloads that are unserialized by the plugin, leading to the creation of arbitrary objects and potentially execution of arbitrary code. This can result in full system compromise within the web server context, granting attackers the ability to read, modify or delete data and obtain privileged access.

Affected Systems

The vulnerability affects installations of the Metagauss RegistrationMagic plugin for WordPress where the plugin version is 6.0.9.7 or earlier. Any site utilizing these plugin releases without an update is susceptible.

Risk and Exploitability

The CVSS rating of 9.8 indicates a severe risk, and although an exact EPSS score is not public, the lack of a KEV listing does not reduce the potential impact. The attack vector is inferred to be an unauthenticated web-based exploit, where an attacker can craft requests through the plugin’s input handling to trigger deserialization.

Generated by OpenCVE AI on August 18, 2026 at 16:24 UTC.

Remediation

Vendor Solution

Update the WordPress RegistrationMagic Plugin to the latest available version (at least 6.0.9.8).


OpenCVE Recommended Actions

  • Update the WordPress RegistrationMagic Plugin to version 6.0.9.8 or later.
  • If an immediate update is not possible, deactivate the RegistrationMagic plugin or remove its files from the WordPress installation to eliminate the vulnerability.
  • Maintain a routine update policy for WordPress core and all plugins, and monitor the vendor’s advisories for any new patches.

Generated by OpenCVE AI on August 18, 2026 at 16:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Metagauss
Metagauss registrationmagic
Wordpress
Wordpress wordpress
Vendors & Products Metagauss
Metagauss registrationmagic
Wordpress
Wordpress wordpress

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
Title WordPress RegistrationMagic plugin <= 6.0.9.7 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Metagauss Registrationmagic
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T19:48:21.449Z

Reserved: 2026-08-12T10:51:08.683Z

Link: CVE-2026-73341

cve-icon Vulnrichment

Updated: 2026-08-18T19:39:41.890Z

cve-icon NVD

Status : Received

Published: 2026-08-18T15:17:02.647

Modified: 2026-08-18T20:17:26.537

Link: CVE-2026-73341

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T18:30:16Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data