CyberRota Analysis
AI-GeneratedThe RegistrationMagic WordPress plugin prior to version 6.0.9.5 is vulnerable due to inadequate validation of PayPal capture details, allowing unauthenticated attackers to finalize high-value registrations using low-value captures. This flaw enables attackers to exploit the system by replaying a single capture across multiple registrations, potentially leading to significant financial losses. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, payee, or prior use against the registration it is finalising: its server-side check only confirms the capture status is COMPLETED. An unauthenticated attacker can therefore finalise an expensive paid registration with any genuinely-completed low-value capture, and replay a single capture across unlimited registrations because captures are not de-duplicated.