RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login

Information

Software Type Plugin
Software Slug custom-registration-form-builder-with-submission-manager (view on wordpress.org)
Software Status Active
Software Author metagauss
Software Website www.registrationmagic.com
Software Downloads 1,773,939
Software Active Installs 10,000
Software Record Last Updated December 22, 2024

Showing 1-20 of 34 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
RegistrationMagic – User Registration Plugin with Custom Registration Forms <= 6.0.2.6 - Unauthenticated Privilege Escalation via Password Recovery Patched CVE-2024-10508 9.8 shaman0x01 November 8, 2024
RegistrationMagic <= 6.0.1.0 - Unauthenticated Stored Cross-Site Scripting Patched CVE-2024-43317 7.2 SOPROBRO August 16, 2024
RegistrationMagic <= 6.0.0.1 - Unauthenticated Stored Cross-Site Scripting Patched CVE-2024-39643 7.2 LVT-tholv2k August 1, 2024
RegistrationMagic <= 5.3.2.0 - Reflected Cross-Site Scripting Patched CVE-2024-33947 6.1 Dimas Maulana April 30, 2024
RegistrationMagic <= 5.3.0.0 - Cross-Site Request Forgery Patched CVE-2024-2951 4.3 Joshua Chan March 26, 2024
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 5.3.1.0 - Authenticated (Contributor+) SQL Injection via Shortcode Patched CVE-2024-1990 8.8 Krzysztof Zając March 26, 2024
RegistrationMagic <= 5.2.5.9 - Reflected Cross-Site Scripting Patched CVE-2024-29113 6.1 beluga March 16, 2024
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 5.3.0.0 - Authenticated (Subscriber+) Privilege Escalation Patched CVE-2024-1991 8.8 Krzysztof Zając March 14, 2024
RegistrationMagic <= 5.2.5.9 - Cross-Site Request Forgery Patched CVE-2024-25935 4.3 Majed Refaea February 20, 2024
RegistrationMagic <= 5.2.5.0 - IP Spoofing Patched CVE-2023-51543 5.3 Brandon James Roldan (tomorrowisnew) December 27, 2023
RegistrationMagic <= 5.2.5.0 - Form Submission Limit Bypass Patched CVE-2023-51544 5.3 Kyle Sanchez December 27, 2023
RegistrationMagic Plugin <= 5.2.4.5 - Authenticated(Administrator+) SQL Injection Patched CVE-2023-50846 6.6 Muhammad Daffa December 21, 2023
RegistrationMagic <= 5.2.3.0 - Missing Authorization Patched CVE-2023-49831 5.3 lttn December 5, 2023
RegistrationMagic <= 5.2.2.6 - Cross-Site Request Forgery Patched CVE-2023-47645 4.3 thiennv November 27, 2023
RegistrationMagic <= 5.2.4.1 - Reflected Cross-Site Scripting via section_id Patched CVE-2023-51509 6.1 Abu Hurayra October 7, 2023
RegistrationMagic <= 5.2.1.0 - Authentication Bypass Patched CVE-2023-2499 9.8 István Márton May 15, 2023
RegistrationMagic <= 5.2.0.5 - Authenticated (Admin+) Insecure Direct Object Reference to Arbitrary User Password Change Patched CVE-2023-2548 6.6 István Márton May 12, 2023
RegistrationMagic <= 5.1.9.2 - Cross-Site Request Forgery leading to Form Metadata Deletion Patched CVE-2023-25991 5.4 Rafshanzani Suhada February 17, 2023
RegistrationMagic <= 5.1.9.2 - Improper Authorization to Price Change Patched CVE-2023-23976 5.3 yuyudhn January 20, 2023
RegistrationMagic <= 5.1.9.2 - Missing Authorization to Unauthenticated Content Injection Patched CVE-2023-23989 5.3 yuyudhn January 20, 2023

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation