WordPress Plugin Vulnerabilities
RegistrationMagic 6.0.0.0 - 6.0.9.8 - Unauthenticated Payment Bypass via Zero Quantity
Description
The plugin does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users to register without paying and obtain an activated account holding the role the form grants.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Vũ Quang Huy
Submitter
Vũ Quang Huy
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-31 (about 2 days ago)
Added
2026-08-31 (about 2 days ago)
Last Updated
2026-08-31 (about 2 days ago)