RegistrationMagic WordPress plugin versions <= 5.0.1.7 contain an authentication bypass caused by missing identity validation in social_login_using_email(), letting unauthenticated users log in as any site user, exploit requires knowing a valid username.
id: CVE-2021-4073
info:
name: RegistrationMagic <= 5.0.1.7 - Authentication Bypass
author: daff
...