Vulnerability record · CVE-2021-24862 · published 10 January 2022
CVE-2021-24862: RegistrationMagic WordPress plugin SQL injection in rm_chronos_ajax
Metagauss · Registrationmagic
The RegistrationMagic WordPress plugin before 5.0.1.6 fails to escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches. This allows SQL injection, letting an attacker manipulate database queries. The flaw is rated high severity with a CVSS 3.1 score of 7.2.
Description
The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.2 high severity, public exploit references, and very high EPSS probability make this a high-priority issue despite requiring high privileges.
What it is
The RegistrationMagic WordPress plugin before 5.0.1.6 fails to escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches. This allows SQL injection, letting an attacker manipulate database queries. The flaw is rated high severity with a CVSS 3.1 score of 7.2.
Impact
An attacker can inject arbitrary SQL into the plugin's batch task duplication query, potentially reading, modifying, or deleting database contents. The CVSS vector indicates high confidentiality, integrity, and availability impact.
Attack surface
The vulnerability is reached over the network through the rm_chronos_ajax AJAX action. The CVSS vector requires high privileges (PR:H) and no user interaction (UI:N), so an authenticated high-privilege user such as an administrator is needed.
Exploitation
CVE-2021-24862 is not listed in CISA KEV, but EPSS gives a 30-day probability of 0.73293 (99.4th percentile), and multiple references are tagged Exploit, indicating public exploit code exists.
What to do
- Update the RegistrationMagic plugin to version 5.0.1.6 or later.
- If immediate patching is not possible, restrict access to the rm_chronos_ajax action and limit high-privilege accounts.
- Review and harden WordPress user roles to reduce the number of accounts with the privileges required to trigger the action.
- Monitor plugin vendor advisvisories for any further updates or workarounds.
Detection
- Inspect web server and WordPress logs for requests to admin-ajax.php with action=rm_chronos_ajax containing SQL metacharacters.
- Enable and review database query logging for anomalous SQL in RegistrationMagic task duplication operations.
- Use a WAF to alert on SQL injection patterns targeting the rm_chronos_ajax parameter.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/165746/WordPress-RegistrationMagic-V-5.0.1.5-SQL-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/Hacker5preme/Exploits/tree/main/Wordpress/CVE-2021-24862 | ExploitThird Party Advisory |
| https://wpscan.com/vulnerability/7d3af3b5-5548-419d-aa32-1f7b51622615 | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/165746/WordPress-RegistrationMagic-V-5.0.1.5-SQL-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/Hacker5preme/Exploits/tree/main/Wordpress/CVE-2021-24862 | ExploitThird Party Advisory |
| https://wpscan.com/vulnerability/7d3af3b5-5548-419d-aa32-1f7b51622615 | ExploitThird Party Advisory |
Track CVE-2021-24862 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-24862), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.