What is CVE-2026-9242?
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Authentication Bypass via Insufficient Verification of Data Authenticity in all versions up to and including 6.0.8.6. This is due to the PayPal IPN `callback` handler being registered as a nopriv AJAX action with no authentication or nonce requirement, and critically because the handler updates the payment log database row with attacker-controlled POST data — including `payment_status` and the `custom` field encoding the target `user_id` — before PayPal IPN validation is performed, meaning the database remains poisoned even when validation subsequently fails. This makes it possible for unauthenticated attackers to authenticate as any WordPress user, including administrators, by submitting a forged IPN request that overwrites a payment log entry's `user_id` with that of a target account, then visiting the success return URL with a legitimately obtained security hash to cause the plugin to issue real WordPress authentication cookies for the targeted account.
The record classifies CVE-2026-9242 under weakness class CWE-345. Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs no prior authentication, needs no user interaction. 1 affected-product entry is recorded, across 1 vendor, listed below. The identifier was first published 100 days ago.
Severity and exploitation probability
- CVSS v3.1 base score
- 5.3 — MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N - CISA KEV
- Not listed in the CISA Known Exploited Vulnerabilities catalog
- Threadlinqs priority
- 2.7/10 — a Threadlinqs composite of the CVSS base score, the EPSS percentile and public exploit availability
- Published
- 2026-06-27
Is CVE-2026-9242 being exploited?
It currently carries a trending score of 30 in the Threadlinqs vulnerability feed.
Affected products and versions
- metagauss: RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login
How to fix CVE-2026-9242
No vendor patch reference has been recorded for CVE-2026-9242 in the tracked sources. Follow the references below for a fix, and treat the products listed above as exposed until the vendor states otherwise.
Threat activity tracking CVE-2026-9242
No threat campaign in the Threadlinqs corpus currently references CVE-2026-9242, in its CVE list or as an indicator. The linkage is recomputed from the live corpus on every daily ingest, so this section fills in as soon as a tracked campaign cites the identifier.
Sources
Enriched from CVE.org, NVD. Last verified by Threadlinqs on . This product uses the NVD API but is not endorsed or certified by the NVD.
Other references
- wordfence.com
- plugins.trac.wordpress.org
- plugins.trac.wordpress.org (class rm paypal service)
- plugins.trac.wordpress.org (class rm public)
- plugins.trac.wordpress.org (class rm public)
Showing 5 of 14 recorded references.