CVE-2026-77793CWE-602
CVE-2026-77793
Medium · published September 2, 2026
What it is
The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-side, allowing unauthenticated users to complete a paid registration without paying and obtain an activated account.
The record
Technical detail
- CVSS v3.1
- 5.3 · MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00194 · 9.1th percentile
- Weakness
- CWE-602 · Client-Side Enforcement of Server-Side Security
- Published
- 2026-09-02T19:17Z
References (1)
EPSS history
Timeline