📦 Registrationmagic

by Metagauss

🔍 What is Registrationmagic?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2017-20208

CRITICAL CVSS 9.8 Oct 18, 2025

This vulnerability allows unauthenticated attackers to execute arbitrary PHP code on WordPress sites using vulnerable versions of the RegistrationMagic plugin. Attackers can inject malicious PHP objec...

CVE-2024-10508

CRITICAL CVSS 9.8 Nov 9, 2024

This vulnerability allows unauthenticated attackers to reset passwords of any WordPress user, including administrators, by exploiting improper token validation in the RegistrationMagic plugin. All Wor...

CVE-2023-2499

CRITICAL CVSS 9.8 May 16, 2023

This vulnerability allows unauthenticated attackers to bypass authentication in WordPress sites using the RegistrationMagic plugin. By exploiting insufficient verification during Google social login, ...

CVE-2021-4073

CRITICAL CVSS 9.8 Dec 14, 2021

CVE-2021-4073 is an authentication bypass vulnerability in the RegistrationMagic WordPress plugin that allows unauthenticated attackers to log in as any user (including administrators) by knowing a va...

CVE-2025-24686

HIGH CVSS 7.1 Jan 31, 2025

This reflected cross-site scripting (XSS) vulnerability in the RegistrationMagic WordPress plugin allows attackers to inject malicious scripts into web pages viewed by other users. The vulnerability a...

CVE-2023-49831

HIGH CVSS 7.5 Dec 9, 2024

This CVE describes a Missing Authorization vulnerability in the RegistrationMagic WordPress plugin that allows attackers to bypass access controls. It affects all versions up to 5.2.3.0, potentially e...

CVE-2023-23976

HIGH CVSS 7.5 Apr 24, 2024

This vulnerability in the RegistrationMagic WordPress plugin allows attackers to bypass access controls and modify arbitrary prices in forms. It affects all WordPress sites using RegistrationMagic ver...

CVE-2024-1990

HIGH CVSS 8.8 Apr 9, 2024

This vulnerability allows authenticated attackers with contributor-level access or higher to perform blind SQL injection attacks via the 'id' parameter in the RegistrationMagic WordPress plugin. Attac...

CVE-2024-29113

HIGH CVSS 7.1 Mar 19, 2024

This vulnerability allows attackers to inject malicious scripts into web pages generated by the RegistrationMagic WordPress plugin. When users visit a specially crafted URL, the script executes in the...

CVE-2023-51509

HIGH CVSS 7.1 Feb 1, 2024

This vulnerability allows attackers to inject malicious scripts into web pages generated by the RegistrationMagic WordPress plugin. When users visit a specially crafted URL, the script executes in the...

CVE-2023-50846

HIGH CVSS 7.6 Dec 28, 2023

This SQL injection vulnerability in the RegistrationMagic WordPress plugin allows attackers to execute arbitrary SQL commands through specially crafted inputs. It affects all WordPress sites using Reg...

CVE-2021-24862

HIGH CVSS 7.2 Jan 10, 2022

This CVE describes a SQL injection vulnerability in the RegistrationMagic WordPress plugin versions before 5.0.1.6. The vulnerability allows attackers to execute arbitrary SQL commands via the rm_chro...

CVE-2024-9390

MEDIUM CVSS 4.8 May 15, 2025

This vulnerability allows high-privilege WordPress users (like administrators) to inject malicious scripts into the RegistrationMagic plugin settings, which then execute when other users view those se...

CVE-2024-43317

MEDIUM CVSS 4.3 Aug 19, 2024

This vulnerability allows attackers to inject malicious scripts into web pages generated by the RegistrationMagic WordPress plugin. When users view affected pages, the scripts execute in their browser...

CVE-2023-51544

MEDIUM CVSS 5.3 Jun 4, 2024

This vulnerability in the RegistrationMagic WordPress plugin allows attackers to bypass form submission limits, enabling functionality misuse. It affects all WordPress sites using RegistrationMagic ve...