Vulnerabilities > Metagauss > Registrationmagic > High

DATE CVE VULNERABILITY TITLE RISK
2024-12-09 CVE-2023-49831 Missing Authorization vulnerability in Metagauss Registrationmagic
Missing Authorization vulnerability in Metagauss User Registration Forms RegistrationMagic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RegistrationMagic: from n/a through 5.2.3.0.
network
low complexity
metagauss CWE-862
7.5
2024-06-04 CVE-2023-51543 Authentication Bypass by Spoofing vulnerability in Metagauss Registrationmagic
Authentication Bypass by Spoofing vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects RegistrationMagic: from n/a through 5.2.5.0.
network
low complexity
metagauss CWE-290
7.5
2024-04-24 CVE-2023-23976 Unspecified vulnerability in Metagauss Registrationmagic
Incorrect Default Permissions vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects RegistrationMagic: from n/a through 5.1.9.2.
network
low complexity
metagauss
7.5
2023-12-28 CVE-2023-50846 SQL Injection vulnerability in Metagauss Registrationmagic
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RegistrationMagic RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login.This issue affects RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: from n/a through 5.2.4.5.
network
low complexity
metagauss CWE-89
7.2
2023-11-30 CVE-2023-47645 Unspecified vulnerability in Metagauss Registrationmagic
Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login allows Cross Site Request Forgery.This issue affects RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login: from n/a through 5.2.2.6.
network
low complexity
metagauss
8.8
2023-05-16 CVE-2023-2548 Authorization Bypass Through User-Controlled Key vulnerability in Metagauss Registrationmagic
The RegistrationMagic plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 5.2.0.5.
network
low complexity
metagauss CWE-639
7.2
2023-03-13 CVE-2023-25991 Unspecified vulnerability in Metagauss Registrationmagic
Cross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic plugin <= 5.1.9.2 versions.
network
low complexity
metagauss
8.8
2022-03-07 CVE-2022-0420 SQL Injection vulnerability in Metagauss Registrationmagic
The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitise and escape the rm_form_id parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform SQL injection attacks
network
low complexity
metagauss CWE-89
7.2
2022-01-10 CVE-2021-24862 Unspecified vulnerability in Metagauss Registrationmagic
The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue
network
low complexity
metagauss
7.2
2021-12-14 CVE-2021-4073 Unspecified vulnerability in Metagauss Registrationmagic
The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin.
network
high complexity
metagauss
8.1