CVE-2026-57770
Deferred Deferred - Pending Action

Deserialization of Untrusted Data in Grand Photography

Vulnerability report for CVE-2026-57770, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-13

Last updated on: 2026-07-13

Assigner: Patchstack

Description

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-13
Last Modified
2026-07-13
Generated
2026-08-02
AI Q&A
2026-07-13
EPSS Evaluated
2026-08-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
themegoods grand_photography to 5.7.8 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-57770 is a high-severity PHP Object Injection vulnerability found in the WordPress Grand Photography Theme versions 5.7.8 and below.

This vulnerability arises from deserialization of untrusted data, which allows attackers to inject malicious objects into the application.

Exploiting this flaw can enable attackers to perform code injection, SQL injection, path traversal, denial of service, and other malicious activities if a suitable POP (Property Oriented Programming) chain exists.

Importantly, the vulnerability is unauthenticated, meaning attackers do not need prior access or credentials to exploit it.

Detection Guidance

There is no specific information provided about detection commands or methods for this vulnerability in the available resources.

Impact Analysis

This vulnerability can have severe impacts including unauthorized code execution, data breaches through SQL injection, unauthorized file access via path traversal, and service disruption through denial of service attacks.

Because the vulnerability is unauthenticated, attackers can exploit it remotely without needing any credentials, increasing the risk of compromise.

If exploited, it could lead to complete system compromise, data loss, or downtime, severely affecting the security and availability of your website.

Compliance Impact

This vulnerability, a deserialization of untrusted data leading to PHP object injection, can significantly impact compliance with standards and regulations like GDPR and HIPAA due to its high severity (CVSS 9.8) and potential for unauthorized access or data manipulation.

  • GDPR: The vulnerability allows attackers to execute arbitrary code, which could lead to unauthorized access to personal data. Under GDPR, organizations must protect personal data from breaches, and failure to mitigate such a vulnerability could result in non-compliance, leading to fines or legal action if a breach occurs.
  • HIPAA: For organizations handling protected health information (PHI), this vulnerability could enable attackers to access, modify, or exfiltrate sensitive health data. HIPAA requires safeguards to protect PHI, and exploitation of this flaw could constitute a breach, triggering reporting obligations and potential penalties.
  • Unauthenticated nature: Since the vulnerability does not require authentication, it increases the risk of widespread exploitation, further elevating compliance risks for organizations subject to data protection regulations.
  • Lack of official patch: The absence of an official patch at the time of disclosure may force organizations to rely on temporary mitigations, which could be insufficient for full compliance with regulatory requirements for timely remediation.
Mitigation Strategies

Immediate mitigation steps include applying the Patchstack mitigation rule to block attacks targeting this vulnerability until an official patch is released.

It is advised to update the Grand Photography theme to a version above 5.7.8 once an official fix is available.

You may also seek assistance from your hosting provider or a developer to help implement these mitigations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57770. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart