The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the identity being requested before returning front-end form submissions, allowing unauthenticated attackers to read other users' form submission data, including personal information.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-30 06:25
Updated : 2026-07-30 16:16
NVD link : CVE-2026-15255
Mitre link : CVE-2026-15255
CVE.ORG link : CVE-2026-15255
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
