cleantalk
Vulnerabilities and Security Researches

RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login, CVE-2025-15520

CVE, Research URL

CVE-2025-15520

Published on
Feb 13, 2026
Research Description
The RegistrationMagic WordPress plugin before 6.0.7.2 checks nonces but not capabilities, allowing for the disclosure of some sensitive data to subscribers and above.
Affected versions
max 6.0.7.2.
Status
vulnerable