cleantalk
Vulnerabilities and Security Researches

RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login, CVE-2026-0929

CVE, Research URL

CVE-2026-0929

Published on
Feb 16, 2026
Research Description
The RegistrationMagic WordPress plugin before 6.0.7.2 does not have proper capability checks, allowing subscribers and above to create forms on the site.
Affected versions
max 6.0.7.2.
Status
vulnerable