Impact
The RegistrationMagic WordPress plugin does not escape a rating field value before rendering it within an HTML attribute on an administrative page. This omission allows an attacker to inject arbitrary JavaScript that is stored in the database and executed whenever an administrator views the page, constituting a stored cross‑site scripting vulnerability.
Affected Systems
Any WordPress site that uses RegistrationMagic version 6.0.9.8 or earlier is vulnerable. The plugin, listed under the vendor name Unknown:RegistrationMagic, is widely distributed as a WordPress add‑on and is responsible for handling user registrations and rating submissions on public‑facing pages.
Risk and Exploitability
There is no publicly available EPSS score, but the flaw permits unauthenticated input that can affect privileged users. Attackers can exploit the vulnerability by submitting malicious content through the rating field, which is then displayed in the admin interface. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog, yet it offers a significant risk due to the potential for privilege escalation and session hijacking.
OpenCVE Enrichment