The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token they can obtain, or to create and log into a new account even when user registration is disabled.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-05 07:17
Updated : 2026-09-08 19:09
NVD link : CVE-2026-77826
Mitre link : CVE-2026-77826
CVE.ORG link : CVE-2026-77826
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication
