CVE-2026-49764
Description
Unauthenticated broken authentication in RegistrationMagic <=6.0.8.6 allows attackers to gain admin access via malicious requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Unauthenticated broken authentication in RegistrationMagic <=6.0.8.6 allows attackers to gain admin access via malicious requests.
Vulnerability
In RegistrationMagic versions up to 6.0.8.6, the plugin suffers from an unauthenticated broken authentication vulnerability. The flaw resides in an endpoint that can be abused by an attacker to perform actions normally restricted to higher privileged users, without any authentication required. The affected versions are all prior to 6.0.8.7. [1]
Exploitation
No authentication is needed to exploit this vulnerability. An attacker can send specially crafted requests to the vulnerable endpoint, triggering the broken authentication. The vulnerability is considered highly dangerous and expected to be used in mass-exploit campaigns targeting thousands of websites regardless of size. [1] The exact sequence of steps is not publicly detailed, but the endpoint allows unauthorized actions.
Impact
Successful exploitation could allow a malicious actor to gain administrator-level access to the WordPress website. This results in full compromise of the site, including the ability to disclose, modify, or delete data, and potentially launch further attacks. [1]
Mitigation
The vulnerability is fixed in version 6.0.8.7. Users should update immediately to that release. For those unable to update, Patchstack has issued a mitigation rule that blocks attacks until the patch is applied. Note that the mitigation may also block legitimate PayPal IPN callbacks on sites using the legacy PayPal IPN payment flow due to the broad nature of the block. [1]
AI Insight generated on Jun 15, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=6.0.8.6
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
1- Wordfence Intelligence Weekly WordPress Vulnerability Report (June 1, 2026 to June 7, 2026)Wordfence Blog · Jun 11, 2026