Impact
Contributor PHP Object Injection exists in Photo Gallery by 10Web plugin versions up to 1.8.46. This flaw allows an attacker to construct a malicious serialized object that, when processed by the plugin, can lead to arbitrary code execution on the WordPress site. The weakness corresponds to CWE-502 and can compromise the confidentiality, integrity, and availability of the affected web application.
Affected Systems
The vulnerability affects the WordPress Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin, all installations running version 1.8.46 or earlier.
Risk and Exploitability
The CVSS score of 8.8 demonstrates high severity. The EPSS score is not available, providing no insight into current exploitation trends, and the vulnerability is not listed in the CISA KEV catalog. Based on the nature of PHP Object Injection, the most likely attack vector involves an authenticated or unauthenticated user submitting a crafted payload to the plugin’s input processing endpoint, leading to code execution on the server.
OpenCVE Enrichment