CVE-2026-105885: WordPress Slider by 10Web plugin <= 1.2.62 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in 10Web Slider by 10Web slider-wd allows Object Injection.This issue affects Slider by 10Web: from n/a through 1.2.62.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Slider by 10Webto a version that resolves this vulnerability.Fixed in 1.2.63
Event History
Frequently Asked Questions
Which installations are affected?
Slider by 10Web versions through 1.2.62 are affected. The affected version range begins at an unspecified earlier version.
What does an attacker need to exploit this issue?
The CVSS vector indicates network-reachable exploitation with low attack complexity, no user interaction, and low privileges required. An unauthenticated attacker is not indicated by the available data.
What could successful exploitation allow?
The issue is rated high severity with high confidentiality, integrity, and availability impact in the CVSS vector. It could therefore affect data disclosure, modification, and service availability.