{"api_version":"1","generated_at":"2026-09-05T09:13:03+00:00","cve":"CVE-2026-77826","urls":{"html":"https://cve.report/CVE-2026-77826","api":"https://cve.report/api/cve/CVE-2026-77826.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-77826","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-77826"},"summary":{"title":"RegistrationMagic 5.0.1.8 - 6.0.9.8 - Unauthenticated Authentication Bypass via Missing Facebook Token Audience Validation","description":"The RegistrationMagic  WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token they can obtain, or to create and log into a new account even when user registration is disabled.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-09-05 07:17:12","updated_at":"2026-09-05 07:17:12"},"problem_types":["CWE-287 Improper Authentication"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/b79a83e8-d7b0-4aa8-b2ba-37a7eecd437b/","name":"https://wpscan.com/vulnerability/b79a83e8-d7b0-4aa8-b2ba-37a7eecd437b/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-77826","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77826","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"RegistrationMagic","version":"affected 5.0.1.8 6.0.9.9 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Mutantgun","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"RegistrationMagic","vendor":"Unknown","versions":[{"lessThan":"6.0.9.9","status":"affected","version":"5.0.1.8","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Mutantgun"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The RegistrationMagic  WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token they can obtain, or to create and log into a new account even when user registration is disabled."}],"problemTypes":[{"descriptions":[{"description":"CWE-287 Improper Authentication","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-05T06:00:05.130Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/b79a83e8-d7b0-4aa8-b2ba-37a7eecd437b/"}],"source":{"discovery":"EXTERNAL"},"title":"RegistrationMagic 5.0.1.8 - 6.0.9.8 - Unauthenticated Authentication Bypass via Missing Facebook Token Audience Validation","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-77826","datePublished":"2026-09-05T06:00:05.130Z","dateReserved":"2026-08-21T14:42:24.977Z","dateUpdated":"2026-09-05T06:00:05.130Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-05 07:17:12","lastModifiedDate":"2026-09-05 07:17:12","problem_types":["CWE-287 Improper Authentication"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"77826","Ordinal":"1","Title":"RegistrationMagic 5.0.1.8 - 6.0.9.8 - Unauthenticated Authentica","CVE":"CVE-2026-77826","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"77826","Ordinal":"1","NoteData":"The RegistrationMagic  WordPress plugin before 6.0.9.9 does not verify which application a Facebook access token was issued to before accepting it as proof of identity, allowing unauthenticated attackers to log in as an existing user whose token they can obtain, or to create and log into a new account even when user registration is disabled.","Type":"Description","Title":"RegistrationMagic 5.0.1.8 - 6.0.9.8 - Unauthenticated Authentica"}]}}}