SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77793

MEDIUM · CVSS 5.3 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The RegistrationMagic WordPress plugin prior to version 6.0.9.9 is vulnerable due to a lack of server-side validation for the total price of paid registrations, enabling unauthenticated users to bypass payment and gain access to activated accounts. This flaw poses a risk of unauthorized account creation and potential abuse of the registration system. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-77793
Severity
MEDIUM
CVSS
5.3
EPSS
0.19%
WordPress

Original NVD Description

The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-side, allowing unauthenticated users to complete a paid registration without paying and obtain an activated account.