QID 730445

Date Published: 2022-04-14

QID 730445: WordPress Plugin RegistrationMagic SQL Injection Vulnerability

RegistrationMagic plugin helps in creating custom Wordpress registration forms, allow user registration, accept payments, track submissions, manage users, analyze stats, assign user roles, automate processes, and send bulk emails.

The RegistrationMagic WordPress plugin before 5.0.2.2 does not sanitize and escape the rm_form_id parameter before using it in a SQL statement in the Automation admin dashboard, allowing high privilege users to perform SQL injection attacks

Affected Versions:
RegistrationMagic plugin prior to 5.0.2.2.
QID Detection Logic:(Unauthenticated)
This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the RegistrationMagic plugin.

Successful exploitation of this vulnerability may allow an authenticated remote attacker to execute arbitrary SQL queries on the affected targets.

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Customers are requested to update to RegistrationMagic 5.0.2.2 or later to mitigate this vulnerability.

    CVEs related to QID 730445

    Software Advisories
    Advisory ID Software Component Link
    RegistrationMagic release notes URL Logo wordpress.org/plugins/custom-registration-form-builder-with-submission-manager/#developers