nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-20208 CVE-2017-20208
CRITICAL
RegistrationMagic - Custom Registration Forms <= 3.7.9.2 - PHP Object Injection
Record summary
CVE-2017-20208 has a selected CVSS score of 9.8 (critical).
Description
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.7.9.3 (exclusive) via deserialization of untrusted input from the is_expired_by_date() function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to fetch a remote file and install it on the site.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 2, 2017 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 20, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User LoginBrowse metagauss / RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User LoginDefault status: unaffected | CVE List | Before 3.7.9.3 | affected |
registrationmagicBrowse metagauss / registrationmagic | VulnCheck | Version data not supplied | |
References
4plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/1733274/custom-registration-form-builder-with-submission-manager wordfence.com
https://www.wordfence.com/blog/2017/10/3-zero-day-plugin-vulnerabilities-exploited-wild wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/c2b79193-f8fc-4ea2-8973-fe292cfb926b?source=cve