Impact
The WordPress Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery plugin contains a PHP deserialization flaw that permits untrusted data to be deserialized, enabling an attacker to instantiate arbitrary PHP objects. This object injection can lead to unauthorized code execution, data manipulation, and compromise of confidentiality, integrity, and availability. The vulnerability is classified as CWE-502.
Affected Systems
Any site running the A WP Life Image Gallery – Lightbox Gallery, Responsive Photo Gallery, Masonry Gallery plugin, version 1.6.0 or older is affected. These releases are vulnerable to object injection through the plugin’s deserialization logic.
Risk and Exploitability
The CVSS base score of 8.8 reflects high severity, while the EPSS score of less than 1 percent indicates a currently low exploitation probability; the problem is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires that an attacker can submit crafted serialized data to the plugin’s deserialization entry points, which is plausible for a role with write access or through exposed endpoints. No publicly documented exploits exist yet, but the risk remains due to the nature of the weakness and potential for future exploitation.
OpenCVE Enrichment