Description

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.7.9.3 (exclusive) via deserialization of untrusted input from the is_expired_by_date() function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to fetch a remote file and install it on the site.

INFO

Published Date :

2025-10-18T03:33:25.276Z

Last Modified :

2026-04-08T17:20:13.875Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2017-20208 vulnerability.

Vendors Products
Metagauss
  • Registrationmagic
Registrationmagic
  • Registrationmagic
Wordpress
  • Wordpress

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact