CVE-2026-0929: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-0929 is a Missing Authorization vulnerability in the RegistrationMagic WordPress plugin (also known as Custom Registration Form Builder with Submission Manager) that allows authenticated subscribers and higher-privileged users to create forms on the site without proper capability checks. It affects all versions of the plugin before 6.0.7.2, and was publicly disclosed on January 26, 2026. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (WPScan, Feedly).

Technical details

The root cause is CWE-862 (Missing Authorization): the plugin fails to enforce proper capability checks on the rm_sort_form_fields AJAX action, specifically the rm_form_quick_add slug. Any authenticated user with at least subscriber-level access can send a crafted POST request to /wp-admin/admin-ajax.php with the action parameter set to rm_sort_form_fields and rm_slug=rm_form_quick_add, along with form parameters, to create a new registration form in the plugin's backend. No elevated privileges or special configuration are required beyond having a valid WordPress account (WPScan).

Impact

Successful exploitation allows low-privileged authenticated users (subscribers) to create arbitrary registration forms within the RegistrationMagic plugin, potentially enabling unauthorized data collection from site visitors or abuse of form-based workflows. While confidentiality and availability are not directly impacted, the integrity of the site's form management is compromised, and malicious forms could be used for phishing or harvesting user data. The scope is limited to the affected WordPress installation (WPScan, Feedly).

Exploitability

A proof-of-concept (PoC) is publicly available via WPScan, demonstrating exploitation through a simple authenticated POST request. The vulnerability requires only a subscriber-level WordPress account, making it accessible to a wide range of potential attackers on sites with open registration. The EPSS score is 0.017% (0.000170), indicating low current probability of exploitation in the wild. No CISA KEV listing or active in-the-wild exploitation campaigns have been reported (WPScan, Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the RegistrationMagic plugin (slug: custom-registration-form-builder-with-submission-manager) in a version below 6.0.7.2. This can be done by checking the plugin's readme.txt or changelog via the site's public URL (e.g., /wp-content/plugins/custom-registration-form-builder-with-submission-manager/readme.txt).
  2. Obtain subscriber account: Register for a standard subscriber account on the target WordPress site, or use existing low-privilege credentials.
  3. Authenticate: Log in to the WordPress site and obtain a valid authentication cookie (e.g., wordpress_logged_in_*).
  4. Send malicious AJAX request: Issue the following authenticated POST request to the site's admin-ajax endpoint:
POST /wp-admin/admin-ajax.php HTTP/2
Cookie: [authenticated subscriber cookie]

action=rm_sort_form_fields&rm_slug=rm_form_quick_add&form_name=WPSCAN&form_type=111111111&user_auto_approval=yes&data=dummy
  1. Verify form creation: Log in to the WordPress admin panel (if accessible) or observe the plugin's "All Forms" section to confirm the unauthorized form has been created (WPScan).

Indicators of compromise

  • Network: Unusual authenticated POST requests to /wp-admin/admin-ajax.php with parameters action=rm_sort_form_fields and rm_slug=rm_form_quick_add from subscriber-level user accounts.
  • Logs: WordPress access logs showing repeated or unexpected POST requests to admin-ajax.php with the above action from non-administrative user sessions.
  • Application: Unexpected or unauthorized forms appearing in the RegistrationMagic plugin's "All Forms" section that were not created by administrators (WPScan).

Mitigation and workarounds

Update the RegistrationMagic plugin to version 6.0.7.2 or later, which introduces proper capability checks for the affected AJAX action. As a temporary workaround, site administrators can disable open user registration to prevent untrusted users from obtaining subscriber accounts, or deactivate the plugin until the update can be applied. No configuration-based fix is available within the vulnerable versions (WPScan).

Community reactions

The vulnerability was discovered and submitted to WPScan by researcher bRpsd, who is also listed as a contributor on Exploit-DB. No significant vendor statements, broader media coverage, or notable community discussion beyond standard vulnerability database listings have been identified for this CVE.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management