SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-57770

CRITICAL · CVSS 9.8 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

A critical deserialization vulnerability in the ThemeGoods Grand Photography plugin allows for object injection, potentially enabling attackers to execute arbitrary code on affected systems. This issue impacts all versions of the plugin up to and including 5.7.8. Organizations using this plugin should prioritize immediate updates or mitigations to safeguard against potential exploitation.

CVE
CVE-2026-57770
Severity
CRITICAL
CVSS
9.8
EPSS
0.30%

Original NVD Description

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.