CVE-2026-15208 Details
Description
The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, payee, or prior use against the registration it is finalising: its server-side check only confirms the capture status is COMPLETED. An unauthenticated attacker can therefore finalise an expensive paid registration with any genuinely-completed low-value capture, and replay a single capture across unlimited registrations because captures are not de-duplicated.
A vulnerability exists in the RegistrationMagic WordPress plugin in versions prior to 6.0.9.5. The issue arises because the plugin's server-side verification of PayPal payments only checks if the payment status is 'COMPLETED', without comparing the amount, currency, payee, or previous usage of the capture against the registration being finalized. This flaw allows an unauthenticated attacker to complete a high-value registration by using a low-value, but genuine, PayPal capture. Additionally, the same PayPal capture can be reused for multiple registrations, as the plugin does not de-duplicate captures.
Users are advised to update the RegistrationMagic WordPress plugin to version 6.0.9.5 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 6, 2026CISA-ADP
Assessed Aug 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/b8c75098-41a9-4b24-9f6b-c3144f230cd8/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-345 | Insufficient Verification of Data Authenticity | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| RegistrationMagic | < 6.0.9.5 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 7, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | [email protected] |
Volerion