CVE-2026-77790 PUBLISHED

RegistrationMagic < 6.0.9.4 - Admin+ SQLi via 'rm_sortby' Parameter

Assigner: WPScan
Reserved: 21.08.2026 Published: 26.08.2026 Updated: 26.08.2026

The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using it in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks.

Product Status

Vendor Unknown
Product RegistrationMagic
Versions Default: unaffected
  • affected from 0 to 6.0.9.4 (excl.)

Credits

  • Meher Sudhakar Abbireddi finder
  • WPScan coordinator

References

Problem Types

  • CWE-89 SQL Injection CWE