SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-15255

MEDIUM · CVSS 5.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The RegistrationMagic plugin for WordPress prior to version 6.0.9.4 is vulnerable due to inadequate validation of one-time passwords stored in cookies, enabling unauthenticated attackers to access and read sensitive form submission data from other users. This vulnerability poses a risk to user privacy and data integrity, making it critical for WordPress site administrators using this plugin to prioritize updates to mitigate potential data breaches. Organizations handling personal information should take immediate action to secure their installations against this threat.

CVE
CVE-2026-15255
Severity
MEDIUM
CVSS
5.3
EPSS
0.20%
WordPress

Original NVD Description

The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the identity being requested before returning front-end form submissions, allowing unauthenticated attackers to read other users' form submission data, including personal information.