Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-15255— RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission Disclosure via IDOR

AI Predicted 7.5 Difficulty: Easy EPSS 0.14% · P4

Possible ATT&CK Techniques 1AI

T1530 · Data from Cloud Storage

Affected Version Matrix 1

VendorProductVersion RangeStatus
UnknownRegistrationMagic< 6.0.9.4affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-15255

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission Disclosure via IDOR
Source: CVE Program / CVE List V5
Vulnerability Description
The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the identity being requested before returning front-end form submissions, allowing unauthenticated attackers to read other users' form submission data, including personal information.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
UnknownRegistrationMagic 0 ~ 6.0.9.4 -

II. Public POCs for CVE-2026-15255

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-15255

登录查看更多情报信息。

Vendor Advisories for CVE-2026-15255 (1)

Same Patch Batch · Unknown · 2026-07-30 · 36 CVEs total

CVE-2026-15054Bit Form < 3.1.2 - Unauthenticated Inactive Form Submission
CVE-2026-15257RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission and User Profile Modificatio
CVE-2026-15240Customer Switching for WooCommerce < 2.1.3 - Customer+ Privilege Escalation to Administrat
CVE-2026-15235Hotel Booking Lite < 6.0.4 - Subscriber+ Sensitive Data Disclosure via Admin Calendar AJAX
CVE-2026-15153WP Hotel Booking < 2.3.2 - Hotel Manager+ SQL Injection via Booking List Search
CVE-2026-14318GiveWP < 4.16.3 - GiveWP Worker+ Stored XSS via Donation Form Template Settings
CVE-2026-14231LifterLMS < 10.0.10 - Subscriber+ Sensitive Information Disclosure via select2_query_posts
CVE-2026-14207LifterLMS < 10.0.10 - Instructor+ Stored XSS via Featured Pricing Information
CVE-2026-12687ProfileGrid < 5.9.9.8 - Unauthenticated Privilege Escalation via Unrestricted Group ID
CVE-2026-15250LatePoint < 5.6.8 - Unauthenticated Booking Object Mass Assignment via Public Booking Funn
CVE-2026-14602Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query Parameter
CVE-2026-14923Sync Post With Other Site < 1.9.3 - Contributor+ Arbitrary Page Creation/Modification
CVE-2026-14223Easy Appointments <= 3.12.26 - Subscriber+ Customer PII Disclosure via IDOR
CVE-2026-14226Easy Appointments <= 3.12.26 - Subscriber+ Sensitive Information Disclosure via REST Appoi
CVE-2026-14592WP Real IP-based Access Control <= 1.3.1 - Unauthenticated Stored XSS via acl_ctrl_addr
CVE-2026-14222Easy Appointments <= 3.12.26 - Contributor+ Connection Deletion via Missing Authorization
CVE-2026-14221Easy Appointments <= 3.12.26 - Contributor+ Appointment Data Disclosure & Modification via
CVE-2026-14188Easy Appointments <= 3.12.26 - Contributor+ Customer Data Disclosure
CVE-2026-13143WP Travel < 11.8.1 - Unauthenticated Payment Bypass via Forged PayPal IPN
CVE-2026-14239Tourmaster < 5.4.8 - Stored XSS via CSRF

Showing top 20 of 36 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-15255

No comments yet


Leave a comment