SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-77792

HIGH · CVSS 7.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The RegistrationMagic plugin for WordPress prior to version 6.0.9.9 is vulnerable due to improper escaping of registration form field values, which can lead to Stored Cross-Site Scripting (XSS) attacks. This vulnerability allows unauthenticated users to inject malicious scripts that execute in the context of high-privilege users, such as administrators, potentially compromising site security. WordPress site administrators and security teams should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-77792
Severity
HIGH
CVSS
7.5
EPSS
0.22%
WordPress

Original NVD Description

The RegistrationMagic WordPress plugin before 6.0.9.9 does not escape a registration form field value before outputting it in an HTML attribute on an administrative page, allowing unauthenticated users to perform Stored Cross-Site Scripting attacks against high privilege users such as admin.