What the vulnerability does
01Description
The Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.8 via deserialization via shortcode of untrusted input. This makes it possible for authenticated attackers, with contributor access and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Explanation of Vulnerability in Simple Terms
02Summary
Logo Showcase Ultimate versions up to 1.3.8 contain a deserialization vulnerability in how they process untrusted data. An authenticated attacker with low privileges can exploit this to read sensitive site data, modify content, or disrupt site availability. The attack requires specific conditions to succeed but poses significant risk to site integrity and confidentiality.
What an attacker can do
03Attacker Capabilities
Read sensitive data, modify site content, or crash the site by sending malicious serialized data.
Potential impact on your site
04Site Impact
Authenticated users with low privileges could compromise site data, content, or availability without additional interaction.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege account on the site; no user interaction required.
Key dates
06Disclosure timeline
March 13, 2024
CVE published
April 8, 2026
Record updated