Plugin Vulnerability Hub
Plugin 48 known issues Latest disclosed Mar 20, 2026

RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Vulnerabilities

Review known vulnerability records for the WordPress plugin RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login (`custom-registration-form-builder-with-submission-manager`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-32498, CVE-2026-24373 and CVE-2025-15520, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
48
High or Critical
18
Patch Coverage
100%
Last Updated
Apr 15, 2026
Priority CVE Quick Links

Fast paths into RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
46
CVE-2020-9457 Critical 4.6.0.4
CVE-2020-9457 RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Privilege Escalation

RegistrationMagic – Custom Registration Forms and User Login <= 4.6.0.3 - Authenticated Settings Import to Privilege Escalation

CVE-2020-9456 Critical 4.6.0.4
CVE-2020-9456 RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Privilege Escalation

RegistrationMagic – Custom Registration Forms and User Login <= 4.6.0.3 - Authenticated Privilege Escalation

CVE-2026-24373 Critical 6.0.7.2
CVE-2026-24373 RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Vulnerability

RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.7.1 - Authentication Bypass

CVE-2025-15403 Critical 6.0.7.2
CVE-2025-15403 RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Privilege Escalation

RegistrationMagic <= 6.0.7.1 - Unauthenticated Privilege Escalation via admin_order

CVE-2024-10508 Critical 6.0.2.7
CVE-2024-10508 RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Privilege Escalation

RegistrationMagic – User Registration Plugin with Custom Registration Forms <= 6.0.2.6 - Unauthenticated Privilege Escalation via Password Recovery

CVE-2023-2499 Critical 5.2.1.1
CVE-2023-2499 RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Vulnerability

RegistrationMagic <= 5.2.1.0 - Authentication Bypass

CVE-2021-4073 Critical 5.0.1.8
CVE-2021-4073 RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Vulnerability

RegistrationMagic <= 5.0.1.7 - Authentication Bypass

CVE-2017-20208 Critical 3.7.9.3
CVE-2017-20208 RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Vulnerability

RegistrationMagic - Custom Registration Forms <= 3.7.9.2 - PHP Object Injection

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
48 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
8 critical and 10 high severity findings.
Recent CVEs
CVE-2026-32498, CVE-2026-24373 and CVE-2025-15520
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-32498
CVE-2026-32498: RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.7.6 - Missing Authorization

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.0.7.6. This makes it possible for unauth...

Published
Mar 20, 2026
Patched Release
6.0.7.7
Affected Versions
Versions up to 6.0.7.6
Next Step
Update to 6.0.7.7 or newer if supported.
Plugin Critical Patched: Yes CVE-2026-24373
CVE-2026-24373: RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.7.1 - Authentication Bypass

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 6.0.7.1. This makes it possible for unauthenticated attackers to bypass authentication.

Published
Mar 12, 2026
Patched Release
6.0.7.2
Affected Versions
Versions up to 6.0.7.1
Next Step
Update to 6.0.7.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-15520
CVE-2025-15520: RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.7.1 - Authenticated (Subscriber+) Information Exposure

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.7.1. This makes it possible for authenticated attackers, with Subscriber-le...

Published
Mar 12, 2026
Patched Release
6.0.7.2
Affected Versions
Versions up to 6.0.7.1
Next Step
Update to 6.0.7.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-32385
CVE-2026-32385: RegistrationMagic <= 6.0.7.6 - Missing Authorization

The RegistrationMagic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.0.7.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an una...

Published
Feb 18, 2026
Patched Release
6.0.7.7
Affected Versions
Versions up to 6.0.7.6
Next Step
Update to 6.0.7.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-14444
CVE-2025-14444: RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.9 - Unauthenticated Payment Bypass via rm_process_paypal_sdk_payment

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to payment bypass due to insufficient verification of data authenticity on the 'process_paypal_sdk_payment' function in all versions up to, and includi...

Published
Feb 17, 2026
Patched Release
6.0.7.0
Affected Versions
Versions up to 6.0.6.9
Next Step
Update to 6.0.7.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-0929
CVE-2026-0929: RegistrationMagic < 6.0.7.2 - Missing Authorization

The RegistrationMagic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 6.0.7.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action...

Published
Feb 16, 2026
Patched Release
6.0.7.2
Affected Versions
Versions before 6.0.7.2
Next Step
Update to 6.0.7.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-1054
CVE-2026-1054: RegistrationMagic <= 6.0.7.4 - Missing Authorization to Unauthenticated Arbitrary Settings Modification

The RegistrationMagic plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.0.7.4. This is due to missing nonce verification and capability checks on the rm_set_otp AJAX action handler. This makes it possible for unauthenticated attackers...

Published
Jan 27, 2026
Patched Release
6.0.7.5
Affected Versions
Versions up to 6.0.7.4
Next Step
Update to 6.0.7.5 or newer if supported.
Plugin Critical Patched: Yes CVE-2025-15403
CVE-2025-15403: RegistrationMagic <= 6.0.7.1 - Unauthenticated Privilege Escalation via admin_order

The RegistrationMagic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.0.7.1. This is due to the 'add_menu' function is accessible via the 'rm_user_exists' AJAX action and allows arbitrary updates to the 'admin_order' setting. Thi...

Published
Jan 16, 2026
Patched Release
6.0.7.2
Affected Versions
Versions up to 6.0.7.1
Next Step
Update to 6.0.7.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-24374
CVE-2026-24374: RegistrationMagic <= 6.0.6.9 - Cross-Site Request Forgery

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.0.6.9. This is due to missing or incorrect nonce validation on a function. This m...

Published
Jan 10, 2026
Patched Release
6.0.7.0
Affected Versions
Versions up to 6.0.6.9
Next Step
Update to 6.0.7.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-13610
CVE-2025-13610: RegistrationMagic <= 6.0.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'RM_Forms' Shortcode

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'RM_Forms' shortcode in all versions up to, and including, 6.0.6.7 due to insufficient input sanitizati...

Published
Dec 15, 2025
Patched Release
6.0.6.8
Affected Versions
Versions up to 6.0.6.7
Next Step
Update to 6.0.6.8 or newer if supported.
Plugin High Patched: Yes CVE-2025-11204
CVE-2025-11204: RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.2 - Authenticated (Administrator+) SQL Injection

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 6.0.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient prepa...

Published
Oct 07, 2025
Patched Release
6.0.6.3
Affected Versions
Versions up to 6.0.6.2
Next Step
Update to 6.0.6.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-2836
CVE-2025-2836: RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.4.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘payment_method’ parameter in all versions up to, and including, 6.0.4.3 due to insufficient input sanitization...

Published
Apr 02, 2025
Patched Release
6.0.4.4
Affected Versions
Versions up to 6.0.4.3
Next Step
Update to 6.0.4.4 or newer if supported.