Registrationmagic
Vendor:
First CVE: Mar 6, 2020 · Active for 6 years
38
Total CVEs
More Total CVEs than 98% of tracked products
5.4
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 51% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Registrationmagic over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 6, 2020
6 years ago
Most Recent CVE
Jun 15, 2026
43 days ago
CVE Severity & Scoring
Registrationmagic38 CVEs
39%
47%
13%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network38 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (94.7%)
High2 (5.3%)
Unknown0 (0.0%)
User Interaction
None24 (63.2%)
Unknown0 (0.0%)
Required14 (36.8%)
Privileges Required
Low8 (21.1%)
High5 (13.2%)
None25 (65.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (38 CVEs).
38 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24862HIGH The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in bat | Jan 10, 2022 | 7.2 | 86 | NO | YES |
CVE-2021-4073HIGH The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site du | Dec 14, 2021 | 8.1 | 43 | NO | YES |
CVE-2026-49764CRITICAL Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions. | Jun 15, 2026 | 9.8 | 35 | NO | NO |
CVE-2017-20208CRITICAL The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.7.9 | Oct 18, 2025 | 9.8 | 31 | NO | NO |
CVE-2023-2499CRITICAL The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.1.0. This is due to insufficient verification on the user be | May 16, 2023 | 9.8 | 30 | NO | NO |
CVE-2024-10508CRITICAL The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up t | Nov 9, 2024 | 9.8 | 29 | NO | NO |
CVE-2020-9458HIGH In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the export function allows remote authenticated users (with minimal privileges) to export submitted form data and set | Mar 6, 2020 | 8.8 | 28 | NO | NO |
CVE-2020-9456HIGH In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (with minimal privileges) to elevate their privileges to admini | Mar 6, 2020 | 8.8 | 28 | NO | NO |
CVE-2020-9454HIGH A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requests on behalf of a site administrator to change all setting | Mar 6, 2020 | 8.8 | 27 | NO | NO |
CVE-2023-25991HIGH Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic plugin <= 5.1.9.2 versions. | Mar 13, 2023 | 8.8 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (38 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.6% of CVEs· 97th percentile
Nuclei
2 CVEs
5.3% of CVEs· 97th percentile
ExploitDB
1 CVE
2.6% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (38 CVEs).
Media Mentions
Signals from CVEs in this product scope (38 CVEs).
Top CNAs Publishing CVEs For Registrationmagic
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.6.0.0 | 2 | 7.1 | 1.6% | 0 | 0 |