CRITICAL🇵🇱 Wersja polska

CVE-2017-20208

CVSS 9.8v3.1pub. 2025-10-18upd. 2025-12-19

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.7.9.3 (exclusive) via deserialization of untrusted input from the is_expired_by_date() function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to fetch a remote file and install it on the site.

🤖 AI Analysis
How it works

The vulnerability results from deserialization of untrusted input data in the is_expired_by_date() function. An attacker without any authentication can pass crafted data that will be deserialized by PHP, leading to PHP object injection. The presence of a POP (Property-Oriented Programming) chain expands exploitation capabilities, allowing the attacker to download a file from a remote server and install it on the attacked WordPress site.

Impact

An attacker can remotely download and install any file on the server, which in practice can lead to complete takeover of the WordPress site, including installation of a backdoor or malicious code.

Mitigation & patch

The RegistrationMagic plugin should be updated to version 3.7.9.3 or newer. The patch is available in the official WordPress plugin repository (changeset 1733274).

Who is affected

RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress in all versions up to 3.7.9.3 (inclusive).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Metagauss Registrationmagic

    APP
    Metagauss
    < 3.7.9.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassDeserialization
CWE
References

Related vulnerabilities

CVE-2024-10508CRITICAL9.8PL ✓same product

RegistrationMagic WordPress — przejęcie konta przez nieprawidłową walidację tokenu resetowania hasła

CVE-2023-2499CRITICAL9.8PL ✓same product

Authentication bypass w wtyczce RegistrationMagic dla WordPress

CVE-2021-4073CRITICAL9.8PL ✓same product

Authentication bypass w RegistrationMagic — logowanie jako dowolny użytkownik WordPress

CVE-2025-24686HIGH7.1same product

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagaus...

CVE-2023-49831HIGH7.5same product

Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submi...