CVE-2026-94122: WordPress Responsive Slider Gallery plugin <= 1.5.5 - PHP Object Injection vulnerability
Published Sep 30, 2026
·Updated
Editor PHP Object Injection in Responsive Slider Gallery <= 1.5.5 versions.
Affected Software
1 affected component
WordPress Responsive Slider Gallery<=1.5.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Responsive Slider Gallery pluginto a version that resolves this vulnerability.Fixed in 1.5.6
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability requires high privileges. The affected attack path is available to an Editor-level user.
2
Can this be exploited remotely without user interaction?
Yes. The vector is network-accessible, requires low attack complexity, and does not require user interaction; however, the attacker must already have the required high-privilege access.
3
What security impact could successful exploitation have?
Successful exploitation can have high impact on confidentiality, integrity, and availability.