VYPR
Critical severity9.8NVD Advisory· Published Jun 15, 2026· Updated Jun 15, 2026

CVE-2026-49764

CVE-2026-49764

Description

Unauthenticated broken authentication in RegistrationMagic <=6.0.8.6 allows attackers to gain admin access via malicious requests.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unauthenticated broken authentication in RegistrationMagic <=6.0.8.6 allows attackers to gain admin access via malicious requests.

Vulnerability

In RegistrationMagic versions up to 6.0.8.6, the plugin suffers from an unauthenticated broken authentication vulnerability. The flaw resides in an endpoint that can be abused by an attacker to perform actions normally restricted to higher privileged users, without any authentication required. The affected versions are all prior to 6.0.8.7. [1]

Exploitation

No authentication is needed to exploit this vulnerability. An attacker can send specially crafted requests to the vulnerable endpoint, triggering the broken authentication. The vulnerability is considered highly dangerous and expected to be used in mass-exploit campaigns targeting thousands of websites regardless of size. [1] The exact sequence of steps is not publicly detailed, but the endpoint allows unauthorized actions.

Impact

Successful exploitation could allow a malicious actor to gain administrator-level access to the WordPress website. This results in full compromise of the site, including the ability to disclose, modify, or delete data, and potentially launch further attacks. [1]

Mitigation

The vulnerability is fixed in version 6.0.8.7. Users should update immediately to that release. For those unable to update, Patchstack has issued a mitigation rule that blocks attacks until the patch is applied. Note that the mitigation may also block legitimate PayPal IPN callbacks on sites using the legacy PayPal IPN payment flow due to the broad nature of the block. [1]

AI Insight generated on Jun 15, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

1