← Vulnerability feed

Vulnerability record · CVE-2021-24862 · published 10 January 2022

CVE-2021-24862: RegistrationMagic WordPress plugin SQL injection in rm_chronos_ajax

Metagauss · Registrationmagic

The RegistrationMagic WordPress plugin before 5.0.1.6 fails to escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches. This allows SQL injection, letting an attacker manipulate database queries. The flaw is rated high severity with a CVSS 3.1 score of 7.2.

7.2 CVSS 3.1 High EPSS 73% · top 0.6% CWE-89 · SQL injection
7.2CVSS 3.1 base score, v2 6.5
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS 7.2 high severity, public exploit references, and very high EPSS probability make this a high-priority issue despite requiring high privileges.

What it is

The RegistrationMagic WordPress plugin before 5.0.1.6 fails to escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches. This allows SQL injection, letting an attacker manipulate database queries. The flaw is rated high severity with a CVSS 3.1 score of 7.2.

Impact

An attacker can inject arbitrary SQL into the plugin's batch task duplication query, potentially reading, modifying, or deleting database contents. The CVSS vector indicates high confidentiality, integrity, and availability impact.

Attack surface

The vulnerability is reached over the network through the rm_chronos_ajax AJAX action. The CVSS vector requires high privileges (PR:H) and no user interaction (UI:N), so an authenticated high-privilege user such as an administrator is needed.

Exploitation

CVE-2021-24862 is not listed in CISA KEV, but EPSS gives a 30-day probability of 0.73293 (99.4th percentile), and multiple references are tagged Exploit, indicating public exploit code exists.

What to do

  • Update the RegistrationMagic plugin to version 5.0.1.6 or later.
  • If immediate patching is not possible, restrict access to the rm_chronos_ajax action and limit high-privilege accounts.
  • Review and harden WordPress user roles to reduce the number of accounts with the privileges required to trigger the action.
  • Monitor plugin vendor advisvisories for any further updates or workarounds.

Detection

  • Inspect web server and WordPress logs for requests to admin-ajax.php with action=rm_chronos_ajax containing SQL metacharacters.
  • Enable and review database query logging for anomalous SQL in RegistrationMagic task duplication operations.
  • Use a WAF to alert on SQL injection patterns targeting the rm_chronos_ajax parameter.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-24862 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-20208Metagauss registrationmagic deserialization of untrusted data vulnerabilityThe RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Inject…EPSS 0.71%9.8CVE-2024-10508Metagauss registrationmagic vulnerabilityThe RegistrationMagic – User Registration Plugin with Custom Registration Forms plugin for WordPress is vulnerable to privilege escalation via accoun…EPSS 1.5%9.8CVE-2024-25935Metagauss registrationmagic missing authorization vulnerabilityMissing Authorization vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.2.5.9.EPSS 0.40%9.8CVE-2023-2499Metagauss registrationmagic authentication bypass via alternate path vulnerabilityThe RegistrationMagic plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.2.1.0. This is due to insuffici…EPSS 1.3%8.8CVE-2024-1990Metagauss registrationmagic sql injection vulnerabilityThe RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to blind SQL Injecti…EPSS 0.82%8.8CVE-2024-1991Metagauss registrationmagic missing authorization vulnerabilityThe RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to privilege escalat…EPSS 0.89%8.8CVE-2023-47645Metagauss registrationmagic cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic RegistrationMagic – Custom Registration Forms, User Registration, Payment, and U…EPSS 0.26%8.8CVE-2023-25991Metagauss registrationmagic cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in RegistrationMagic plugin <= 5.1.9.2 versions.EPSS 0.25%

Source: NIST National Vulnerability Database (record CVE-2021-24862), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.