What is CVE-2026-15208?
CVE-2026-15208 is a critical vulnerability in the RegistrationMagic WordPress plugin before version 6.0.9.5. An unauthenticated attacker can finalize a registration by exploiting a server-side check that only verifies the PayPal capture status as COMPLETED, without comparing the amount, currency, payee, or prior use. Updating to the latest patched version is strongly recommended.
Azərbaycanca: CVE-2026-15208, RegistrationMagic WordPress plaginində 6.0.9.5 versiyasından əvvəl mövcud olan kritik zəiflikdir. Bu zəiflik səbəbindən autentifikasiya olunmamış hücumçu PayPal ödənişinin yalnız statusunu yoxlayaraq, məbləğ, valyuta və ya ödəniş sahibi kimi detalları təsdiqləmədən qeydiyyat prosesini tamamlaya bilər. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: shared vendor: PayPal
FAQ1
How can an attacker exploit CVE-2026-15208 to complete a registration?
The attacker exploits a server-side check that only verifies the PayPal capture status as COMPLETED, without comparing the amount, currency, payee, or prior use, allowing them to finalize the registration without authentication.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.