Description
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.
Published: 2026-07-13
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Grand Photography theme on WordPress implements deserialization of untrusted PHP data, which enables object injection as identified by CWE-502. An attacker who can supply a crafted serialized payload can cause WordPress to instantiate malicious objects, leading to execution of arbitrary PHP code and granting the attacker complete control over the site and its underlying server.

Affected Systems

Any WordPress installation that includes the ThemeGoods Grand Photography theme version 5.7.8 or earlier is vulnerable. The flaw can be triggered during theme loading, administrative functions, or any operation that processes serialized theme data, regardless of whether the theme is actively selected.

Risk and Exploitability

The CVSS score of 9.8 places the vulnerability in the Critical range, indicating a high severity level. The EPSS score of less than 1% suggests that the likelihood of exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog. Based solely on the description, it is inferred that the attack vector involves supplying a malicious serialized object to the theme during normal WordPress execution. If exploited, the attacker would gain full compromise of the WordPress installation, affecting confidentiality, integrity, and availability.

Generated by OpenCVE AI on July 31, 2026 at 11:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable the Grand Photography theme or switch immediately to a non‑vulnerable theme to stop execution of the protected code path.
  • Check the vendor’s website or official channels for a released fix or newer theme version, and apply it as soon as it becomes available.
  • Review the WordPress installation for unauthorized code, monitor logs for deserialization attempts, and consider restoring from a clean backup if compromise is suspected.

Generated by OpenCVE AI on July 31, 2026 at 11:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Themegoods
Themegoods grand Photography
Wordpress
Wordpress wordpress
Vendors & Products Themegoods
Themegoods grand Photography
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.
Title WordPress Grand Photography theme <= 5.7.8 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Themegoods Grand Photography
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:50.018Z

Reserved: 2026-06-25T08:04:47.959Z

Link: CVE-2026-57770

cve-icon Vulnrichment

Updated: 2026-07-13T16:01:59.991Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:00:05Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data