Security Advisory

CVE-2026-15208

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-06 17:07:32
Last updated 2026-08-06 17:07:32
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, payee, or prior use against the registration it is finalising: its server-side check only confirms the capture status is COMPLETED. An unauthenticated attacker can therefore finalise an expensive paid registration with any genuinely-completed low-value capture, and replay a single capture across unlimited registrations because captures are not de-duplicated.