vulnerability

WordPress Plugin: custom-registration-form-builder-with-submission-manager: CVE-2017-20208: Deserialization of Untrusted Data

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Oct 2, 2017
Added
Oct 21, 2025
Modified
Oct 21, 2025

Description

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.7.9.3 (exclusive) via deserialization of untrusted input from the is_expired_by_date() function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to fetch a remote file and install it on the site.

Solution

custom-registration-form-builder-with-submission-manager-plugin-cve-2017-20208
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.