Description
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.
Published: 2026-08-31
Score: 7.4 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In WordPress RegistrationMagic plugin versions 6.0.9.8 and earlier, an unauthenticated user can bypass the authentication checks, enabling them to access administrative functions or create privileged accounts. This vulnerability falls under the Common Weakness Enumeration 288, which represents broken or missing authentication. The impact of exploiting this flaw is the potential for an attacker to gain unauthorized privileges within the WordPress installation, thereby compromising the confidentiality, integrity, and availability of the site content and configuration.

Affected Systems

The affected system is the WordPress site that has the RegistrationMagic plugin installed. Any deployment using Metagauss RegistrationMagic plugin version 6.0.9.8 or older is vulnerable and requires an upgrade to version 6.0.9.9 or later.

Risk and Exploitability

The CVSS score for this flaw is 7.4, indicating a high severity. The EPSS value is not provided, and the vulnerability is not listed in CISA’s KEV catalog. Because the flaw allows unauthenticated users to gain elevated access, the likely attack vector is a direct request to the registration or login endpoints exposed by the plugin. No prerequisites such as elevated privilege or network connectivity beyond internet access are required to exploit this weakness.

Generated by OpenCVE AI on August 31, 2026 at 21:37 UTC.

Remediation

Vendor Solution

Update the WordPress RegistrationMagic Plugin to the latest available version (at least 6.0.9.9).


OpenCVE Recommended Actions

  • Update the RegistrationMagic plugin to version 6.0.9.9 or later to remove the authentication bypass.
  • Revoke any administrative accounts that may have been created or accessed through the vulnerable plugin before applying the update.
  • Audit recent registrations and logins for anomalies, and apply stricter role permissions or additional authentication measures while the plugin is updated.

Generated by OpenCVE AI on August 31, 2026 at 21:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Metagauss
Metagauss registrationmagic
Wordpress
Wordpress wordpress
Vendors & Products Metagauss
Metagauss registrationmagic
Wordpress
Wordpress wordpress

Mon, 31 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.
Title WordPress RegistrationMagic plugin <= 6.0.9.8 - Broken Authentication vulnerability
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Metagauss Registrationmagic
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-31T20:30:54.290Z

Reserved: 2026-08-28T09:18:05.695Z

Link: CVE-2026-82225

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T21:17:53.320

Modified: 2026-08-31T21:17:53.320

Link: CVE-2026-82225

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T21:45:04Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel