← Back to CVE search

CVE-2026-77790

RegistrationMagic

Description

The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using it in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks.

EPSS 0.19%Risk 0
View source
Published
2026-08-26 06:16:29
Affected versions
<6.0.9.4
Type
Web application
Last modified
2026-08-26 16:30:52
Vector
Pending