Impact
WordPress RegistrationMagic versions up to 6.0.9.7 are vulnerable to unauthenticated PHP Object Injection. The flaw allows an attacker to supply crafted payloads that are unserialized by the plugin, leading to the creation of arbitrary objects and potentially execution of arbitrary code. This can result in full system compromise within the web server context, granting attackers the ability to read, modify or delete data and obtain privileged access.
Affected Systems
The vulnerability affects installations of the Metagauss RegistrationMagic plugin for WordPress where the plugin version is 6.0.9.7 or earlier. Any site utilizing these plugin releases without an update is susceptible.
Risk and Exploitability
The CVSS rating of 9.8 indicates a severe risk, and although an exact EPSS score is not public, the lack of a KEV listing does not reduce the potential impact. The attack vector is inferred to be an unauthenticated web-based exploit, where an attacker can craft requests through the plugin’s input handling to trigger deserialization.
OpenCVE Enrichment