The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using it in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks.
We have discovered 1,509 live websites that are affected by CVE-2026-77790.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,509 live websites (80% of Custom Registration Form Builder With Submission Manager install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 179 versions ( 98% of all versions) |
| 520 websites | |
| 121 websites | |
| 115 websites | |
| 70 websites | |
| 59 websites | |
| 42 websites | |
| 39 websites | |
| 36 websites | |
| 32 websites | |
| 30 websites |
| .com | 572 websites |
| .org | 183 websites |
| .it | 92 websites |
| .de | 50 websites |
| .net | 39 websites |
| .co.uk | 36 websites |
| .nl | 30 websites |
| .eu | 23 websites |
| .pl | 21 websites |
| .ca | 19 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***.edu | **,*** | ||
| ***********.co | ***,*** | ||
| *****************.com | ***,*** | ||
| ********.org | ***,*** | ||
| *********.com | ***,*** | ||
| *********.org | ***,*** | ||
| *************.com | ***,*** | ||
| *************.com | ***,*** | ||
| ******************.com | ***,*** | ||
| ********.***.in | ***,*** |
FAQ