Unrated severityNVD Advisory· Published Sep 5, 2026
RegistrationMagic 5.0.1.8 - 6.0.9.8 - Unauthenticated Authentication Bypass via Missing Facebook Token Audience Validation
CVE-2026-77826
Description
The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token they can obtain, or to create and log into a new account even when user registration is disabled.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <6.0.9.9
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/b79a83e8-d7b0-4aa8-b2ba-37a7eecd437b/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.