Description
Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions.
Published: 2026-09-30
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Remote code execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a PHP object injection flaw found in the WordPress Responsive Slider Gallery plugin versions up to 1.5.5. An attacker who can persuade the application to unserialize crafted data can execute arbitrary PHP code, potentially compromising the host server, exfiltrating data, and providing a foothold for further attacks. This weakness is a classic instance of CWE‑502.

Affected Systems

Vendors: A WP Life. Product: Responsive Slider Gallery plugin. Affected versions: any installation of the plugin up to and including 1.5.5; recommended to upgrade to 1.5.6 or later.

Risk and Exploitability

The CVSS score of 7.2 indicates high severity, while the lack of an EPSS score and absence from the CISA KEV catalog suggest currently low exploitation probability. The likely attack vector is through the plugin’s editor interface, which allows authenticated users with editing permissions to submit data that is deserialized by the plugin. An attacker with the appropriate privileges could supply malicious serialized objects that the plugin will blindly process, leading to remote code execution.

Generated by OpenCVE AI on September 30, 2026 at 15:48 UTC.

Remediation

Vendor Solution

Update the WordPress Responsive Slider Gallery Plugin to the latest available version (at least 1.5.6).


OpenCVE Recommended Actions

  • Upgrade the Responsive Slider Gallery plugin to version 1.5.6 or later
  • If an update is not feasible, disable or remove the plugin entirely until an update can be applied
  • Configure the WordPress instance to restrict editor access to the least privileged users and enforce strict input validation to avoid unserialization of untrusted data

Generated by OpenCVE AI on September 30, 2026 at 15:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions.
Title WordPress Responsive Slider Gallery plugin <= 1.5.5 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-30T13:27:05.961Z

Reserved: 2026-09-20T16:03:26.251Z

Link: CVE-2026-94122

cve-icon Vulnrichment

Updated: 2026-09-30T13:17:56.250Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T13:17:24.700

Modified: 2026-09-30T14:17:40.727

Link: CVE-2026-94122

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T16:00:15Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data