CVE-2026-77826 PUBLISHED

RegistrationMagic 5.0.1.8 - 6.0.9.8 - Unauthenticated Authentication Bypass via Missing Facebook Token Audience Validation

Assigner: WPScan
Reserved: 21.08.2026 Published: 05.09.2026 Updated: 05.09.2026

The RegistrationMagic WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token they can obtain, or to create and log into a new account even when user registration is disabled.

Product Status

Vendor Unknown
Product RegistrationMagic
Versions Default: unaffected
  • affected from 5.0.1.8 to 6.0.9.9 (excl.)

Credits

  • Mutantgun finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE