The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.7.9.3 (exclusive) via deserialization of untrusted input from the is_expired_by_date() function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to fetch a remote file and install it on the site.
The vulnerability results from deserialization of untrusted input data in the is_expired_by_date() function. An attacker without any authentication can pass crafted data that will be deserialized by PHP, leading to PHP object injection. The presence of a POP (Property-Oriented Programming) chain expands exploitation capabilities, allowing the attacker to download a file from a remote server and install it on the attacked WordPress site.
An attacker can remotely download and install any file on the server, which in practice can lead to complete takeover of the WordPress site, including installation of a backdoor or malicious code.
The RegistrationMagic plugin should be updated to version 3.7.9.3 or newer. The patch is available in the official WordPress plugin repository (changeset 1733274).
RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress in all versions up to 3.7.9.3 (inclusive).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMetagauss Registrationmagic
APPMetagauss< 3.7.9.3
Related vulnerabilities
RegistrationMagic WordPress — przejęcie konta przez nieprawidłową walidację tokenu resetowania hasła
Authentication bypass w wtyczce RegistrationMagic dla WordPress
Authentication bypass w RegistrationMagic — logowanie jako dowolny użytkownik WordPress
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagaus...
Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submi...