Description
The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token they can obtain, or to create and log into a new account even when user registration is disabled.
Published: 2026-09-05
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The RegistrationMagic WordPress plugin fails to verify the audience attribute of a Facebook access token before accepting it as proof of identity. This omission lets an attacker who obtains a valid token log in as any existing user or create a new account even when user registration is disabled, effectively bypassing authentication controls. The result is full compromise of the target user accounts, including access to whatever permissions that user holds, and can lead to broader site compromise if the account is an administrator. The vulnerability is an instance of improper authentication (CWE‑287).

Affected Systems

The vulnerability affects the RegistrationMagic WordPress plugin versions 5.0.1.8 through 6.0.9.8 inclusive. Versions 6.0.9.9 and later are believed to contain the fix (inferred from available statements).

Risk and Exploitability

Based on the description, the likely attack vector involves an attacker who has obtained a Facebook access token issued to an approved application. No EPSS score is provided and the issue is not listed in the CISA KEV catalog, yet the impact is high because the flaw permits credential impersonation without additional permissions. Once the token is in hand, it can be submitted to the plugin’s authentication endpoint to log in or create an account regardless of site registration settings. This makes the vulnerability exploitable in any WordPress environment running the affected plugin and exposes all sites that rely on Facebook login to potential account takeover.

Generated by OpenCVE AI on September 5, 2026 at 08:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update RegistrationMagic to the latest available version, which is believed to address the issue of missing audience validation (inferred that v6.0.9.9 or later implements the fix).
  • If an update cannot be performed immediately, disable the Facebook login feature or block access to the token validation endpoint until a secure implementation is available.
  • Verify all WordPress plugins and core are current, and remove or harden any other social login plugins that may present similar validation gaps.
  • Monitor plugin activity logs for unusual authentication attempts and consider implementing additional application‑level logging or rate‑limiting on OAuth token submissions.

Generated by OpenCVE AI on September 5, 2026 at 08:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 05 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Registrationmagic
Registrationmagic registrationmagic
Wordpress
Wordpress wordpress
Vendors & Products Registrationmagic
Registrationmagic registrationmagic
Wordpress
Wordpress wordpress

Sat, 05 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Sat, 05 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token they can obtain, or to create and log into a new account even when user registration is disabled.
Title RegistrationMagic 5.0.1.8 - 6.0.9.8 - Unauthenticated Authentication Bypass via Missing Facebook Token Audience Validation
References

Subscriptions

Registrationmagic Registrationmagic
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-05T06:00:05.130Z

Reserved: 2026-08-21T14:42:24.977Z

Link: CVE-2026-77826

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-05T07:17:12.063

Modified: 2026-09-05T07:17:12.063

Link: CVE-2026-77826

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T09:00:07Z

Weaknesses