Impact
The Vulnerability impacts the RegistrationMagic WordPress plugin, versions 6.0.0.0 through 6.0.9.8, by failing to validate a quantity multiplier supplied by users during paid registration. As a result, an attacker can submit a registration form with a quantity of zero, causing the payment calculation to return a total of zero and bypassing the payment process. The user receives an activated account with the role granted by the registration form, enabling unauthorized access or privilege escalation. This flaw corresponds to CWE-472, Consequence of Improper Input Validation.
Affected Systems
Affected systems are WordPress installations that use the RegistrationMagic plugin, versions 6.0.0.0 to 6.0.9.8. The vulnerability is present in all builds of the plugin before 6.0.9.9; any site running those versions without patching is vulnerable.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, and the EPSS score is unavailable, suggesting limited data on exploitation frequency. The vulnerability is not yet listed in the CISA KEV catalog. An attacker can exploit this flaw without authentication by submitting a registration form with a zero quantity multiplier from any network. Successful exploitation grants the user an activated account with whatever role the form assigns, potentially including administrative privileges. No special access or additional software is required; the attack is purely client‑side input manipulation.
OpenCVE Enrichment