Sceawere
Vulnerability Detail
CVE-2026-94122UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Responsive Slider Gallery PHP Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 3h ago
- Vendor
- A WP Life
- Product
- Responsive Slider Gallery
- Attack Type
- CWE-502 Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-09-30T13:17:24.700Z",
"pubdate": "2026-09-30T13:17:24.700Z",
"executiveSummary": "The Responsive Slider Gallery plugin for WordPress, specifically versions 1.5.5 and below, contains a critical PHP Object Injection vulnerability.\nThis vulnerability stems from the insecure handling of serialized data passed to the application, allowing an attacker to manipulate objects within the PHP application memory space.\nSuccessful exploitation permits unauthorized attackers to trigger arbitrary code execution, manipulate application logic, or execute system-level commands, contingent upon the availability of suitable gadget chains present in the environment.\nThe vulnerability poses a severe risk to site integrity, confidentiality, and availability, as it enables full compromise of the affected WordPress installation.\nExploitation requires no specialized administrative privileges if the vulnerable endpoint is accessible to unauthenticated users, though it is often leveraged post-authentication depending on the specific implementation of the deserialization routine.\nOrganizations using this plugin are at high risk of remote code execution (RCE) and data exfiltration if they have not remediated the underlying flaw.",
"technicalDetails": "The root cause of the vulnerability lies in the use of the 'unserialize()' function on unsanitized user-supplied input. PHP Object Injection occurs when an application deserializes untrusted data without validation, allowing an attacker to inject specifically crafted serialized strings that represent objects of arbitrary classes available within the application's scope.\nWhen the vulnerable component processes this serialized payload, it instantiates the malicious object. If the environment contains 'gadget chains'—existing classes with magic methods like '__destruct()', '__wakeup()', or '__toString()'—the attacker can leverage these methods to execute arbitrary code or perform unintended actions during the object's lifecycle.\nThe attack flow typically follows a structured progression: First, the attacker identifies a parameter or endpoint that accepts serialized data as input. Second, the attacker performs reconnaissance to identify available classes within the WordPress core or other installed plugins to construct a viable gadget chain. Third, the attacker crafts a serialized payload designed to trigger these gadgets, often leading to file system access, database manipulation, or remote code execution via functions such as 'eval()', 'system()', or 'call_user_func_array()'.\nIn the context of Responsive Slider Gallery <= 1.5.5, the vulnerability is localized to the server-side processing of input parameters that are passed directly to the deserialization routine. Because WordPress environments often include various plugins with large object graphs, the probability of finding a functional gadget chain is significantly high. Once the payload is successfully injected and deserialized, the resulting object instantiation leads to the execution of the attacker's logic in the context of the web server process.\nPost-exploitation impact is catastrophic; it allows for the persistence of malicious backdoors, exfiltration of sensitive configuration data (such as 'wp-config.php' database credentials), and complete unauthorized control over the server environment. The lack of input validation or the failure to use secure alternatives like 'json_decode()' for data transport is the fundamental architectural deficiency enabling this security failure."
}