What the vulnerability does
01Description
Incorrect Privilege Assignment vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Privilege Escalation.This issue affects RegistrationMagic: from n/a through <= 6.0.7.1.
Explanation of Vulnerability in Simple Terms
02Summary
RegistrationMagic versions up to 6.0.7.1 contain a privilege escalation vulnerability that allows unauthenticated attackers to gain full control over the application. The vulnerability requires specific network conditions to exploit but does not require user interaction. Affected sites should update immediately to a patched version.
What an attacker can do
03Attacker Capabilities
Gain unauthorized access and modify or delete data without authentication.
Potential impact on your site
04Site Impact
Attackers can read, modify, or delete sensitive registration data and user information without logging in.
Conditions required to exploit
05Prerequisites
Network access to the vulnerable application; no authentication or user interaction required.
Key dates
06Disclosure timeline
March 25, 2026
CVE published
April 28, 2026
Record updated