
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14444 is a payment bypass vulnerability in the RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress. It affects all versions up to and including 6.0.6.9 and allows unauthenticated attackers to bypass paid registration by manipulating client-supplied payment status values in the process_paypal_sdk_payment function without completing an actual PayPal transaction. The vulnerability was published on February 18, 2026, and carries a CVSS v3.1 base score of 5.3 (Medium) (Red Hat CVE).
The root cause is classified as CWE-345 (Insufficient Verification of Data Authenticity). The process_paypal_sdk_payment function trusts client-supplied values to determine whether a PayPal payment was completed, without performing server-side verification against the PayPal API to confirm the transaction's authenticity. An unauthenticated attacker can craft an HTTP request to this function with a manipulated payment status (e.g., marking the payment as successful) to activate their account without making a real payment. No authentication or user interaction is required, and the attack is executable remotely over the network (Red Hat CVE).
Successful exploitation allows unauthenticated users to register and activate accounts on WordPress sites using RegistrationMagic without paying the required fees, directly undermining the site's monetization and access control mechanisms. The integrity impact is low and scoped to the affected application — there is no confidentiality or availability impact. Sites offering paid memberships, gated content, or premium services are most at risk of financial loss and unauthorized access (Red Hat CVE).
There is no public evidence of active in-the-wild exploitation or weaponized exploit kits for CVE-2025-14444 at this time. The EPSS score is very low at approximately 0.008%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Red Hat CVE).
process_paypal_sdk_payment endpoint and its expected parameters.process_paypal_sdk_payment after the payment step and modify the payment status parameter to indicate a successful payment (e.g., setting status to COMPLETED or equivalent).process_paypal_sdk_payment endpoint with no corresponding PayPal transaction ID that can be verified in PayPal's transaction history.api.paypal.com) following registration events, which would be expected in a properly implemented payment flow.Users should update the RegistrationMagic plugin to a version beyond 6.0.6.9 that addresses this vulnerability. As a temporary workaround, site administrators can disable paid registration forms until a patched version is applied, or manually verify PayPal transactions against the PayPal dashboard before approving new registrations. Administrators should also audit recently created accounts on paid forms to identify any that may have bypassed payment (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."