Registrationmagic

Vendor:

First CVE: Mar 6, 2020 · Active for 6 years

38
Total CVEs
More Total CVEs than 98% of tracked products
5.4
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 51% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Registrationmagic over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 6, 2020
6 years ago
Most Recent CVE
Jun 15, 2026
43 days ago

CVE Severity & Scoring

Registrationmagic38 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network38 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (94.7%)
High2 (5.3%)
Unknown0 (0.0%)
User Interaction
None24 (63.2%)
Unknown0 (0.0%)
Required14 (36.8%)
Privileges Required
Low8 (21.1%)
High5 (13.2%)
None25 (65.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (38 CVEs).

38 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in bat
Jan 10, 20227.286NOYES
The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site du
Dec 14, 20218.143NOYES
Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.
Jun 15, 20269.835NONO
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.7.9
Oct 18, 20259.831NONO
The RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.1.0. This is due to insufficient verification on the user be
May 16, 20239.830NONO
The RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up t
Nov 9, 20249.829NONO
In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the export function allows remote authenticated users (with minimal privileges) to export submitted form data and set
Mar 6, 20208.828NONO
In the RegistrationMagic plugin through 4.6.0.3 for WordPress, the user controller allows remote authenticated users (with minimal privileges) to elevate their privileges to admini
Mar 6, 20208.828NONO
A CSRF vulnerability in the RegistrationMagic plugin through 4.6.0.3 for WordPress allows remote attackers to forge requests on behalf of a site administrator to change all setting
Mar 6, 20208.827NONO
Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic plugin <= 5.1.9.2 versions.
Mar 13, 20238.826NONO

Exploit Exposure

Signals from CVEs in this product scope (38 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.6% of CVEs· 97th percentile
Nuclei
2 CVEs
5.3% of CVEs· 97th percentile
ExploitDB
1 CVE
2.6% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (38 CVEs).

Media Mentions

Signals from CVEs in this product scope (38 CVEs).

Top CNAs Publishing CVEs For Registrationmagic

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.6.0.027.11.6%00