Authentication vulnerability in RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login 5.2.1.0

The RegistrationMagic plugin for WordPress has a security flaw in versions prior to 5.2.1.0. This flaw allows unauthorized users to log in as any existing user on the site, such as an administrator, if they have access to the email address associated with that user. This is because the plugin does not properly verify the user who is attempting to log in using a Google social login.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.