MEDIUMVulnerability

CVE-2026-77790

The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using it in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks.

Properties

severity
MEDIUM
score
5.5
epss_score
0.00208
cve_id
CVE-2026-77790
vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
published_at
2026-08-26T06:16:29.910
last_modified
2026-09-03T16:18:22.747
epss_percentile
0.10951

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-77790 — Ninja Signal Threat Intelligence | Ninja Signal