Junglewise Threat Intelligence

CVE-2026-57770: ThemeGoods Grand Photography PHP object injection

CVE-2026-57770 · Severity: critical · CVSS 9.8 · Published 2026-07-13

Technologies: ThemeGoods Grand Photography. Vendors: ThemeGoods.

Executive brief

ThemeGoods Grand Photography, a popular WordPress theme for photography websites, contains a critical security flaw. An attacker can exploit this to gain full control over the website, potentially leading to data theft, site defacement, or the installation of malicious software. This vulnerability can be exploited remotely without needing any login credentials.

Technical details

A PHP Object Injection vulnerability exists in the ThemeGoods Grand Photography theme for WordPress (versions up to and including 5.7.8) due to the deserialization of untrusted data. This flaw allows an unauthenticated remote attacker to inject arbitrary PHP objects. If a suitable Property-Oriented Programming (POP) chain is present within the environment, the attacker could achieve remote code execution, perform SQL injection, or conduct path traversal. As of the advisory date, no official patch has been released by the vendor.

Affected products

  • ThemeGoods Grand Photography <= 5.7.8

Timeline

  • 2026-01-02: other: Vulnerability reported by Tran Nguyen Bao Khanh
  • 2026-07-09: advisory: Patchstack published advisory
  • 2026-07-13: disclosed: CVE published to NVD

References

Related threats