cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forcustom-registration-form-builder-with-submission-manager custom-registration-form-builder-with-submission-manager

Direction: descending
Jan 28, 2026

RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login # CVE-2026-24374

CVE, Research URL

CVE-2026-24374

Date
Jan 22, 2026
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Cross Site Request Forgery.This issue affects RegistrationMagic: from n/a through <= 6.0.6.9.
Affected versions
max 6.0.6.9.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2025-15403

CVE, Research URL

CVE-2025-15403

Date
Jan 17, 2026
Research Description
The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.0.7.1. This is due to the 'add_menu' function is accessible via the 'rm_user_exists' AJAX action and allows arbitrary updates to the 'admin_order' setting. This makes it possible for unauthenticated attackers to injecting an empty slug into the order parameter, and manipulate the plugin's menu generation logic, and when the admin menu is subsequently built, the plugin adds 'manage_options' capability for the target role. Note: The vulnerability can only be exploited unauthenticated, but further privilege escalation requires at least a subscriber user.
Affected versions
max 6.0.7.2.
Status
vulnerable
Jan 10, 2026

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2025-13610

CVE, Research URL

CVE-2025-13610

Date
Dec 15, 2025
Research Description
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'RM_Forms' shortcode in all versions up to, and including, 6.0.6.7 due to insufficient input sanitization and output escaping on the 'theme' attribute. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 6.0.6.8.
Status
vulnerable
Nov 10, 2025

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2017-20208

CVE, Research URL

CVE-2017-20208

Date
Oct 18, 2025
Research Description
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.7.9.3 (exclusive) via deserialization of untrusted input from the is_expired_by_date() function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to fetch a remote file and install it on the site.
Affected versions
max 3.7.9.3.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2025-11204

CVE, Research URL

CVE-2025-11204

Date
Oct 08, 2025
Research Description
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 6.0.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. An unauthenticated attacker could utilize an injected Cross-Site Scripting via user-agent on form submission to leverage this to achieve Reflected Cross-Site Scripting.
Affected versions
max 6.0.6.3.
Status
vulnerable
May 19, 2025

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2024-9390

CVE, Research URL

CVE-2024-9390

Date
May 16, 2025
Research Description
The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
max 6.0.2.1.
Status
vulnerable
Apr 05, 2025

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2025-2836

CVE, Research URL

CVE-2025-2836

Date
Apr 04, 2025
Research Description
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘payment_method’ parameter in all versions up to, and including, 6.0.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 6.0.4.4.
Status
vulnerable
Feb 01, 2025

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2025-24686

CVE, Research URL

CVE-2025-24686

Date
Jan 31, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss User Registration Forms RegistrationMagic allows Reflected XSS. This issue affects RegistrationMagic: from n/a through 6.0.3.3.
Affected versions
max 6.0.3.4.
Status
vulnerable
Nov 10, 2024

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2024-10508

CVE, Research URL

CVE-2024-10508

Date
Nov 09, 2024
Research Description
The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0.2.6. This is due to the plugin not properly validating the password reset token prior to updating a user's password. This makes it possible for unauthenticated attackers to reset the password of arbitrary users, including administrators, and gain access to these accounts.
Affected versions
max 6.0.2.7.
Status
vulnerable
Aug 20, 2024

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2024-43317

CVE, Research URL

CVE-2024-43317

Date
Aug 20, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Metagauss User Registration Team RegistrationMagic allows Cross-Site Scripting (XSS).This issue affects RegistrationMagic: from n/a through 6.0.1.0.
Affected versions
max 6.0.1.1.
Status
vulnerable
Aug 04, 2024

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2024-39643

CVE, Research URL

CVE-2024-39643

Date
Aug 02, 2024
Research Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in RegistrationMagic Forms RegistrationMagic allows Stored XSS.This issue affects RegistrationMagic: from n/a through 6.0.0.1.
Affected versions
max 6.0.0.2.
Status
vulnerable
Jun 10, 2024

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2023-49831

CVE, Research URL

CVE-2023-49831

Date
Dec 09, 2024
Research Description
Missing Authorization vulnerability in Metagauss User Registration Forms RegistrationMagic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RegistrationMagic: from n/a through 5.2.3.0.
Affected versions
max 5.2.3.1.
Status
vulnerable
Jun 07, 2024

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2021-4073

CVE, Research URL

CVE-2021-4073

Date
Dec 14, 2021
Research Description
The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.
Affected versions
max 5.0.2.2.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2021-24862

CVE, Research URL

CVE-2021-24862

Date
Jan 10, 2022
Research Description
The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue
Affected versions
max 5.0.1.6.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2020-9457

CVE, Research URL

CVE-2020-9457

Date
Mar 07, 2020
Research Description
The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to import custom vulnerable forms and change form settings via class_rm_form_settings_controller.php, resulting in privilege escalation.
Affected versions
max 4.6.0.4.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2020-8436

CVE, Research URL

CVE-2020-8436

Date
Mar 12, 2020
Research Description
XSS was discovered in the RegistrationMagic plugin 4.6.0.0 for WordPress via the rm_form_id, rm_tr, or form_name parameter.
Affected versions
max 4.6.0.3.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2020-9454

CVE, Research URL

CVE-2020-9454

Date
Mar 07, 2020
Research Description
A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requests on behalf of a site administrator to change all settings for the plugin, including deleting users, creating new roles with escalated privileges, and allowing PHP file uploads via forms.
Affected versions
max 4.6.0.4.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2020-9455

CVE, Research URL

CVE-2020-9455

Date
Mar 07, 2020
Research Description
The RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote authenticated users (with minimal privileges) to send arbitrary emails on behalf of the site via class_rm_user_services.php send_email_user_view.
Affected versions
max 4.6.0.4.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2020-9456

CVE, Research URL

CVE-2020-9456

Date
Mar 07, 2020
Research Description
In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (with minimal privileges) to elevate their privileges to administrator via class_rm_user_controller.php rm_user_edit.
Affected versions
max 4.6.0.4.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2021-24648

CVE, Research URL

CVE-2021-24648

Date
Feb 01, 2022
Research Description
The RegistrationMagic WordPress plugin before 5.0.1.9 does not sanitise and escape the rm_search_value parameter before outputting back in an attribute, leading to a Reflected Cross-Site Scripting
Affected versions
max 5.0.2.2.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2020-8435

CVE, Research URL

CVE-2020-8435

Date
Mar 12, 2020
Research Description
An issue was discovered in the RegistrationMagic plugin 4.6.0.0 for WordPress. There is SQL injection via the rm_analytics_show_form rm_form_id parameter.
Affected versions
max 4.6.0.3.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2022-0420

CVE, Research URL

CVE-2022-0420

Date
Mar 07, 2022
Research Description
The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform SQL injection attacks
Affected versions
max 5.0.2.2.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2020-9458

CVE, Research URL

CVE-2020-9458

Date
Mar 07, 2020
Research Description
In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the export function allows remote authenticated users (with minimal privileges) to export submitted form data and settings via class_rm_form_controller.php rm_form_export.
Affected versions
max 3.7.9.3.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2023-23976

CVE, Research URL

CVE-2023-23976

Date
Apr 24, 2024
Research Description
Incorrect Default Permissions vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects RegistrationMagic: from n/a through 5.1.9.2.
Affected versions
max 5.1.9.3.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2023-23989

CVE, Research URL

CVE-2023-23989

Date
Apr 24, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.1.9.2.
Affected versions
max 5.1.9.3.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2023-25991

CVE, Research URL

CVE-2023-25991

Date
Mar 13, 2023
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic plugin <= 5.1.9.2 versions.
Affected versions
max 5.1.9.3.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2023-2499

CVE, Research URL

CVE-2023-2499

Date
May 16, 2023
Research Description
The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.1.0. This is due to insufficient verification on the user being supplied during a Google social login through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email.
Affected versions
max 5.2.1.1.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2023-2548

CVE, Research URL

CVE-2023-2548

Date
May 16, 2023
Research Description
The RegistrationMagic plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 5.2.0.5. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers, with administrator-level permissions and above, to change user passwords and potentially take over super-administrator accounts in multisite setup.
Affected versions
max 5.2.4.2.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2023-51544

CVE, Research URL

CVE-2023-51544

Date
Jun 04, 2024
Research Description
Improper Control of Interaction Frequency vulnerability in Metagauss RegistrationMagic allows Functionality Misuse.This issue affects RegistrationMagic: from n/a through 5.2.5.0.
Affected versions
max 5.2.5.1.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2023-50846

CVE, Research URL

CVE-2023-50846

Date
Dec 29, 2023
Research Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RegistrationMagic RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login.This issue affects RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: from n/a through 5.2.4.5.
Affected versions
max 5.2.4.6.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2023-51543

CVE, Research URL

CVE-2023-51543

Date
Jun 04, 2024
Research Description
Authentication Bypass by Spoofing vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects RegistrationMagic: from n/a through 5.2.5.0.
Affected versions
max 5.2.5.1.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2023-51509

CVE, Research URL

CVE-2023-51509

Date
Feb 01, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login allows Reflected XSS.This issue affects RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: from n/a through 5.2.4.1.
Affected versions
max 5.2.6.0.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2023-47645

CVE, Research URL

CVE-2023-47645

Date
Nov 30, 2023
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login allows Cross Site Request Forgery.This issue affects RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: from n/a through 5.2.2.6.
Affected versions
max 5.2.3.0.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2024-25935

CVE, Research URL

CVE-2024-25935

Date
Apr 11, 2024
Research Description
Missing Authorization vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.2.5.9.
Affected versions
max 5.2.6.0.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2024-1991

CVE, Research URL

CVE-2024-1991

Date
Apr 10, 2024
Research Description
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the update_users_role() function in all versions up to, and including, 5.3.0.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to escalate their privileges to that of an administrator
Affected versions
max 5.3.1.0.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2024-1990

CVE, Research URL

CVE-2024-1990

Date
Apr 10, 2024
Research Description
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to blind SQL Injection via the ‘id’ parameter of the RM_Form shortcode in all versions up to, and including, 5.3.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected versions
max 5.3.2.0.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2024-33947

CVE, Research URL

CVE-2024-33947

Date
May 03, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic allows Reflected XSS.This issue affects RegistrationMagic: from n/a through 5.3.2.0.
Affected versions
max 5.3.2.1.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2024-29113

CVE, Research URL

CVE-2024-29113

Date
Mar 19, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic allows Reflected XSS.This issue affects RegistrationMagic: from n/a through 5.2.5.9.
Affected versions
max 5.2.6.0.
Status
vulnerable

RegistrationMagic &#8211; Custom Registration Forms, User Registration, Payment, and User Login # CVE-2024-2951

CVE, Research URL

CVE-2024-2951

Date
Mar 26, 2024
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.3.0.0.
Affected versions
max 5.3.1.0.
Status
vulnerable