PT-2026-32599 · WordPress · Smart Post Show
Vilaysone Chanthavong
·
Published
2026-04-14
·
Updated
2026-04-14
·
CVE-2026-3017
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts versions prior to 3.0.13
Description
The plugin is susceptible to PHP Object Injection due to the deserialization of untrusted input within the
import shortcodes() function. This allows authenticated attackers with Administrator-level access or higher to inject a PHP Object. This issue requires a POP chain (a sequence of gadgets used to achieve a specific goal during deserialization) to be present in another installed plugin or theme to have an impact. If such a chain exists, it could enable the deletion of arbitrary files, retrieval of sensitive data, or code execution.Recommendations
Update to a version later than 3.0.12.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Smart Post Show