PT-2026-54509 · WordPress · Registrationmagic

·

CVE-2026-12158

·

Published

2026-07-01

·

Updated

2026-07-01

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RegistrationMagic – User Registration Forms Plugin versions prior to 6.0.9.2
Description This issue involves a Cross-Site Request Forgery (CSRF) flaw, which occurs when a web application fails to verify that a request was intentionally initiated by the user. The flaw exists in the process request() function due to missing or incorrect nonce validation. An unauthenticated attacker can exploit this by tricking a site administrator into clicking a malicious link, allowing the attacker to escalate the privileges of a form submitter to administrator by creating a malicious Chronos automation task executed via WordPress cron.
Recommendations Update RegistrationMagic – User Registration Forms Plugin to version 6.0.9.2 or later. As a temporary mitigation, restrict access to the process request() function to prevent unauthorized requests.

Fix

LPE

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12158

Affected Products

Registrationmagic