PT-2026-3341 · WordPress · Registrationmagic

Published

2026-01-17

·

Updated

2026-01-22

·

CVE-2025-15403

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RegistrationMagic versions prior to 6.0.7.1
Description The RegistrationMagic plugin for WordPress is susceptible to a privilege escalation issue. The add menu function is accessible through the rm user exists AJAX action, allowing manipulation of the admin order setting. An unauthenticated attacker can inject an empty slug into the order parameter, influencing the plugin's menu generation. This manipulation results in the addition of 'manage options' capability for a target role when the admin menu is built. Exploitation requires at least a subscriber user for further escalation after the initial unauthenticated access.
Recommendations Versions prior to 6.0.7.1 should be updated to a newer, fixed version.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-15403

Affected Products

Registrationmagic