CVE-2026-57770: WordPress Grand Photography theme <= 5.7.8 - PHP Object Injection vulnerability
Published Jul 13, 2026
·Updated
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through <= 5.7.8.
Affected Software
1 affected component
ThemeGoods Grand Photography<=5.7.8
Event History
Jul 13, 2026
CVE Published
via MITRE·08:41 AM
Data Sourced
via MITRE·08:41 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-57770?
CVE-2026-57770 has a critical severity rating of 9.8.
2
How do I fix CVE-2026-57770?
To fix CVE-2026-57770, update the Grand Photography theme to version 5.7.9 or later.
3
What type of vulnerability is CVE-2026-57770?
CVE-2026-57770 is a PHP Object Injection vulnerability due to deserialization of untrusted data.
4
Which software is affected by CVE-2026-57770?
The vulnerability affects the ThemeGoods Grand Photography theme versions from n/a up to and including 5.7.8.
5
What are the potential impacts of CVE-2026-57770?
CVE-2026-57770 can lead to significant security risks including remote code execution and data manipulation.