CyberRota Analysis
AI-GeneratedA critical deserialization vulnerability in the ThemeGoods Grand Photography plugin allows for object injection, potentially enabling attackers to execute arbitrary code on affected systems. This issue impacts all versions of the plugin up to and including 5.7.8. Organizations using this plugin should prioritize immediate updates or mitigations to safeguard against potential exploitation.
CVE
CVE-2026-57770
Severity
CRITICAL
CVSS
9.8
EPSS
0.30%
Original NVD Description
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.