CVE-2026-12158Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.0.9.1. This is due to missing or incorrect nonce validation on the process_request function. This makes it possible for unauthenticated attackers to escalate the privileges of an arbitrary form submitter to administrator by creating a malicious Chronos automation task that is executed via WordPress cron via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-07-01); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-01: 1Mentions · 2026-07-02: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-02: 107-0107-02
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • 大島義裕@yoshihiro_oh
    Disclosure

    WordPressプラグイン「RegistrationMagic」にユーザー権限昇格の脆弱性 https://www.cve.org/CVERecord?id=CVE-2026-12158 重大性スコア(CVS):8.8 高い 本脆弱性を悪用された場合、管理者の操作をきっかけとして、サイトに登録されているユーザーの権限が意図せず引き上げられ、管理者権限を与えられる可能性があります。

    Post summary

    A CVE-2026-12158 vulnerability in the WordPress plugin RegistrationMagic can allow privilege escalation to administrator level; the vulnerability is rated high severity (8.8), but no PoC, exploit, or patch information is provided.

    10120239
    2.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-12158 Cross-Site Request Forgery in RegistrationMagic User Registration Forms Plugin Up to 6.0.9.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-12158

    Post summary

    The post announces CVE-2026-12158, a CSRF flaw in RegistrationMagic plugin versions up to 6.0.9.1, with no further exploitation or patch information provided.

    0000093
    4.1K followersView on X

Explore more