CVE-2026-15208

MEDIUM CVSS 3.1: 5.3 EPSS 0.12%
Updated Aug 07, 2026
WordPress
Parameter Value
CVSS 5.3 (MEDIUM)
Affected Versions before 6.0.9.5
Type CWE-345 (Insufficient Verification of Data)
Vendor WordPress
Public PoC No

The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, payee, or prior use against the registration it is finalising: its server-side check only confirms the capture status is COMPLETED. An unauthenticated attacker can therefore finalise an expensive paid registration with any genuinely-completed low-value capture, and replay a single capture across unlimited registrations because captures are not de-duplicated.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1