
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0929 is a Missing Authorization vulnerability in the RegistrationMagic WordPress plugin (also known as Custom Registration Form Builder with Submission Manager) that allows authenticated subscribers and higher-privileged users to create forms on the site without proper capability checks. It affects all versions of the plugin before 6.0.7.2, and was publicly disclosed on January 26, 2026. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (WPScan, Feedly).
The root cause is CWE-862 (Missing Authorization): the plugin fails to enforce proper capability checks on the rm_sort_form_fields AJAX action, specifically the rm_form_quick_add slug. Any authenticated user with at least subscriber-level access can send a crafted POST request to /wp-admin/admin-ajax.php with the action parameter set to rm_sort_form_fields and rm_slug=rm_form_quick_add, along with form parameters, to create a new registration form in the plugin's backend. No elevated privileges or special configuration are required beyond having a valid WordPress account (WPScan).
Successful exploitation allows low-privileged authenticated users (subscribers) to create arbitrary registration forms within the RegistrationMagic plugin, potentially enabling unauthorized data collection from site visitors or abuse of form-based workflows. While confidentiality and availability are not directly impacted, the integrity of the site's form management is compromised, and malicious forms could be used for phishing or harvesting user data. The scope is limited to the affected WordPress installation (WPScan, Feedly).
A proof-of-concept (PoC) is publicly available via WPScan, demonstrating exploitation through a simple authenticated POST request. The vulnerability requires only a subscriber-level WordPress account, making it accessible to a wide range of potential attackers on sites with open registration. The EPSS score is 0.017% (0.000170), indicating low current probability of exploitation in the wild. No CISA KEV listing or active in-the-wild exploitation campaigns have been reported (WPScan, Feedly).
custom-registration-form-builder-with-submission-manager) in a version below 6.0.7.2. This can be done by checking the plugin's readme.txt or changelog via the site's public URL (e.g., /wp-content/plugins/custom-registration-form-builder-with-submission-manager/readme.txt).wordpress_logged_in_*).POST /wp-admin/admin-ajax.php HTTP/2
Cookie: [authenticated subscriber cookie]
action=rm_sort_form_fields&rm_slug=rm_form_quick_add&form_name=WPSCAN&form_type=111111111&user_auto_approval=yes&data=dummy/wp-admin/admin-ajax.php with parameters action=rm_sort_form_fields and rm_slug=rm_form_quick_add from subscriber-level user accounts.admin-ajax.php with the above action from non-administrative user sessions.Update the RegistrationMagic plugin to version 6.0.7.2 or later, which introduces proper capability checks for the affected AJAX action. As a temporary workaround, site administrators can disable open user registration to prevent untrusted users from obtaining subscriber accounts, or deactivate the plugin until the update can be applied. No configuration-based fix is available within the vulnerable versions (WPScan).
The vulnerability was discovered and submitted to WPScan by researcher bRpsd, who is also listed as a contributor on Exploit-DB. No significant vendor statements, broader media coverage, or notable community discussion beyond standard vulnerability database listings have been identified for this CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."