Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 29 Jan 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Metagauss
Metagauss registrationmagic Wordpress Wordpress wordpress |
|
| Vendors & Products |
Metagauss
Metagauss registrationmagic Wordpress Wordpress wordpress |
Wed, 28 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 28 Jan 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The RegistrationMagic plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.0.7.4. This is due to missing nonce verification and capability checks on the rm_set_otp AJAX action handler. This makes it possible for unauthenticated attackers to modify arbitrary plugin settings, including reCAPTCHA keys, security settings, and frontend menu titles. | |
| Title | RegistrationMagic <= 6.0.7.4 - Missing Authorization to Unauthenticated Arbitrary Settings Modification | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:27:26.132Z
Reserved: 2026-01-16T17:03:05.877Z
Link: CVE-2026-1054
Updated: 2026-01-28T14:43:39.103Z
Status : Deferred
Published: 2026-01-28T08:16:03.230
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-1054
No data.
OpenCVE Enrichment
Updated: 2026-04-15T19:00:12Z