Impact
The vulnerability is a PHP object injection flaw found in the WordPress Responsive Slider Gallery plugin versions up to 1.5.5. An attacker who can persuade the application to unserialize crafted data can execute arbitrary PHP code, potentially compromising the host server, exfiltrating data, and providing a foothold for further attacks. This weakness is a classic instance of CWE‑502.
Affected Systems
Vendors: A WP Life. Product: Responsive Slider Gallery plugin. Affected versions: any installation of the plugin up to and including 1.5.5; recommended to upgrade to 1.5.6 or later.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity, while the lack of an EPSS score and absence from the CISA KEV catalog suggest currently low exploitation probability. The likely attack vector is through the plugin’s editor interface, which allows authenticated users with editing permissions to submit data that is deserialized by the plugin. An attacker with the appropriate privileges could supply malicious serialized objects that the plugin will blindly process, leading to remote code execution.
OpenCVE Enrichment