CVE-2017-20208
CRITICAL EXPLOITEDRegistrationMagic <3.7.9.3 - Code Injection
Title source: llmDescription
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.7.9.3 (exclusive) via deserialization of untrusted input from the is_expired_by_date() function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to fetch a remote file and install it on the site.
References (3)
Scores
CVSS v3
9.8
EPSS
0.0033
EPSS Percentile
55.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Intel
VulnCheck KEV
2017-10-02
Classification
CWE
CWE-502
Status
published
Affected Products (1)
metagauss/registrationmagic
< 3.7.9.3
Timeline
Published
Oct 18, 2025
Tracked Since
Feb 18, 2026