Impact
An unauthenticated attacker can inject and execute arbitrary client‑side scripts in the web browser of any user who views content rendered by the RegistrationMagic plugin. The vulnerability arises from improper sanitization of user‑supplied input and allows malicious JavaScript, leading to cookie theft, session hijacking, defacement, or redirect to phishing sites.
Affected Systems
The flaw affects the Metagauss RegistrationMagic WordPress plugin for all versions up to and including 6.0.9.8. WordPress sites that have not upgraded beyond these releases and host the plugin are vulnerable.
Risk and Exploitability
The CVSS v3 score is 7.1, indicating a medium‑to‑high severity. No EPSS score is currently available, and the issue is not listed in CISA KEV, so there are no publicly known exploit campaigns at this time. The likely attack vector is an unauthenticated web request that submits crafted form data and then redirects the victim to a page that triggers the XSS payload.
OpenCVE Enrichment