CVE-2026-15255
Vulnerability Description
The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the identity being requested before returning front-end form submissions, allowing unauthenticated attackers to read other users' form submission data, including personal information.
Vulnerability Details
Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
RegistrationMagic
Discussion (0)
Add Comment
No comments yet. Be the first!