Description
The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using it in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks.
EPSS 0.19%Risk 0
View source- Published
- 2026-08-26 06:16:29
- Affected versions
- <6.0.9.4
- Type
- Web application
- Last modified
- 2026-08-26 16:30:52
- Vector
- Pending