CVE-2026-9242
Last modified
CVE-2026-9242 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Verification of Data Authenticity in all versions up to and including 6.0.8.6. This is due to the PayPal IPN `callback` handler being registered as a nopriv AJAX action with no authentication or nonce requirement, and critically because the handler updates the payment log database row with attacker-controlled POST data — including `payment_status` and the `custom` field encoding the target `user_id` — before PayPal IPN validation is performed, meaning the database remains poisoned even when validation subsequently fails. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Verification of Data Authenticity in all versions up to and including 6.0.8.6. This is due to the PayPal IPN `callback` handler being registered as a nopriv AJAX action with no authentication or nonce requirement, and critically because the handler updates the payment log database row with attacker-controlled POST data — including `payment_status` and the `custom` field encoding the target `user_id` — before PayPal IPN validation is performed, meaning the database remains poisoned even when validation subsequently fails. This makes it possible for unauthenticated attackers to authenticate as any WordPress user, including administrators, by submitting a forged IPN request that overwrites a payment log entry's `user_id` with that of a target account, then visiting the success return URL with a legitimately obtained security hash to cause the plugin to issue real WordPress authentication cookies for the targeted account.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| metagauss | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | <= 6.0.8.6 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-9242?
How severe is CVE-2026-9242?
How do I fix CVE-2026-9242?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-92411The WP Delicious WordPress plugin before 1.10.8 does not va…
- CVE-2026-92413A flaw has been found in Artifex MuPDF up to b6d17493700c621…4.3
- CVE-2026-92416A vulnerability has been found in Open5GS up to 2.8.0. Affec…4.3
- CVE-2026-92417A vulnerability was found in Open5GS up to 2.8.0. This affec…6.5
- CVE-2026-92418A vulnerability was determined in ChangeWeDer crm up to c07b…3.5
- CVE-2026-92419WEBCON BPS is vulnerable to Insecure Direct Object Reference…5.3
- CVE-2026-92420The Hydra Booking — Appointment Scheduling & Booking Calenda…3.8
- CVE-2026-92421The Hydra Booking — Appointment Scheduling & Booking Calenda…4.7
- CVE-2026-92422The Meow Gallery WordPress plugin before 5.5.5 does not prop…6.5
- CVE-2026-92423The Meow Gallery WordPress plugin before 5.5.5 does not perf…2.7
- CVE-2026-92425The Hydra Booking — Appointment Scheduling & Booking Calenda…5.5
- CVE-2026-9243The Plus Addons for Elementor plugin for WordPress is vulner…6.4
Are you affected by CVE-2026-9242?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
