
CVE-2026-0929 The RegistrationMagic WordPress plugin before 6.0.7.2 does not have proper capability checks, allowing subscribers and above to create forms on the site. https://www.cve.org/CVERecord?id=CVE-2026-0929
Post summary
The post reports a privilege‑escalation flaw in the RegistrationMagic WordPress plugin, where users with subscriber-level permissions can create forms due to missing capability checks; no exploit, patch, or in‑the‑wild activity is mentioned.

