Sceawere

Vulnerability Detail

CVE-2026-105885UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Object Injection in 10Web Slider

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
2h ago
Vendor
10Web
Product
Slider by 10Web
Attack Type
Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Deserialization of Untrusted Data vulnerability in 10Web Slider by 10Web slider-wd allows Object Injection.This issue affects Slider by 10Web: from n/a through 1.2.62.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-10T14:16:37.087Z",
  "pubdate": "2026-10-10T14:16:37.087Z",
  "executiveSummary": "The Slider by 10Web plugin is susceptible to an Object Injection vulnerability caused by the insecure deserialization of untrusted data.\nThis vulnerability, present in versions n/a through 1.2.62, allows an attacker to inject arbitrary PHP objects into the application scope.\nBy manipulating serialized data, an unauthenticated or authenticated attacker can leverage existing 'gadget chains' within the application or its dependencies to execute arbitrary code, bypass security controls, or manipulate sensitive data.\nThe risk is critical, as successful exploitation facilitates remote code execution (RCE) on the underlying server, potentially leading to full site compromise.\nThe vulnerability stems from the plugin's failure to validate or sanitize serialized inputs before processing them through PHP's unserialize() function.\nAttackers do not require high-level administrative privileges to initiate the attack if the vulnerable endpoint is exposed, making this a significant security risk for installations running the affected versions.",
  "technicalDetails": "The root cause of this vulnerability is the insecure use of the PHP unserialize() function on user-supplied input within the 10Web Slider plugin. When an application passes untrusted input directly into unserialize() without prior validation or cryptographic signature verification, the PHP engine instantiates objects based on the serialized string provided.\nAn attacker can craft a malicious serialized string that, when processed, creates an object of an arbitrary class available within the application's environment. This process is referred to as PHP Object Injection.\nThe attack flow involves several stages: First, the attacker identifies an input vector—such as a specific HTTP parameter, cookie, or POST body—that the Slider by 10Web plugin passes to the unserialize() function. Second, the attacker performs reconnaissance to identify 'gadget chains'. A gadget chain consists of existing classes within the application or bundled libraries (like common WordPress core classes or third-party dependencies) that implement magic methods such as __wakeup(), __destruct(), or __toString().\nThird, the attacker constructs a payload that instantiates these gadget classes. Upon deserialization, the magic methods are triggered automatically. By chaining these methods, the attacker can influence the state of the application, manipulate properties of existing objects, or execute arbitrary system commands if a 'POP' (Property-Oriented Programming) chain leading to sensitive sinks—like system(), eval(), or file_put_contents()—is discovered.\nThe vulnerability affects all versions of Slider by 10Web from n/a through 1.2.62. Because the deserialization occurs during the handling of incoming requests, the attack can often be performed remotely without requiring elevated privileges if the vulnerable function is exposed via a public-facing API or form submission.\nPost-exploitation impact is severe. Because the code is executed within the context of the web server process, the attacker can achieve remote code execution, install persistent backdoors, access the database, or pivot deeper into the internal network infrastructure. Furthermore, if the web server process runs with high privileges, the attacker could gain unauthorized access to the underlying operating system and sensitive configuration files."
}
CVE-2026-105885: Object Injection in 10Web Slider (HIGH Severity, CVSS: 8.8) | Sceawere