CVE-2026-15255

RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission Disclosure via IDOR

The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in a cookie belongs to the identity being requested before returning front-end form submissions, allowing unauthenticated attackers to read other users' form submission data, including personal information.


We have discovered 1,968 live websites that are affected by CVE-2026-15255.

Run a Free Instant Scan




Affected Software

Product  Custom Registration Form Builder With Submission Manager
Category Wordpress Plugins
Vulnerable Domains1,968 live websites (100% of Custom Registration Form Builder With Submission Manager install base)
Vulnerable Versions
  • from 0 through 6.0.9.4
Vulnerable Versions Count183 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-639 Authorization Bypass Through User-Controlled Key



Details

  • Published - Jul 30, 2026
  • Updated - Jul 30, 2026

Credits

  • Jonatan Buskila (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-15255
United States731 websites



Germany164 websites
Italy148 websites
GB87 websites
France82 websites
Canada53 websites
Netherlands48 websites
South Africa42 websites
Australia37 websites
Spain36 websites

Website Distribution by TLD

Number of websites using CVE-2026-15255
.com751 websites
.org266 websites
.it114 websites
.de78 websites
.net51 websites
.co.uk42 websites
.nl41 websites
.eu29 websites
.ca26 websites
.pl25 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-15255

Top websites that are affected by CVE-2026-15255. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.edu United States**,***
**.net United States**,***
***********.co United States***,***
*****************.com United States***,***
********.org United States***,***
*********.com United States***,***
*********.org United States***,***
*************.com United States***,***
*************.com Germany***,***
******************.com United States***,***
See full domain list

FAQ

CVE-2026-15255 is Authorization Bypass Through User-Controlled Key in Custom Registration Form Builder With Submission Manager
A total of 1,968 websites have been identified as vulnerable to CVE-2026-15255, based on global website indexing conducted by WebTechSurvey.
The Custom Registration Form Builder With Submission Manager is affected by the CVE-2026-15255 vulnerability.
Custom Registration Form Builder With Submission Manager versions up to 6.0.9.4 are vulnerable to CVE-2026-15255.
CVE-2026-15255 is resolved in version 6.0.9.4 of Custom Registration Form Builder With Submission Manager.