Impact
In WordPress RegistrationMagic plugin versions 6.0.9.8 and earlier, an unauthenticated user can bypass the authentication checks, enabling them to access administrative functions or create privileged accounts. This vulnerability falls under the Common Weakness Enumeration 288, which represents broken or missing authentication. The impact of exploiting this flaw is the potential for an attacker to gain unauthorized privileges within the WordPress installation, thereby compromising the confidentiality, integrity, and availability of the site content and configuration.
Affected Systems
The affected system is the WordPress site that has the RegistrationMagic plugin installed. Any deployment using Metagauss RegistrationMagic plugin version 6.0.9.8 or older is vulnerable and requires an upgrade to version 6.0.9.9 or later.
Risk and Exploitability
The CVSS score for this flaw is 7.4, indicating a high severity. The EPSS value is not provided, and the vulnerability is not listed in CISA’s KEV catalog. Because the flaw allows unauthenticated users to gain elevated access, the likely attack vector is a direct request to the registration or login endpoints exposed by the plugin. No prerequisites such as elevated privilege or network connectivity beyond internet access are required to exploit this weakness.
OpenCVE Enrichment