A WP Life Image Gallery PHP Object Injection Vulnerability

Vulnerability

A deserialization vulnerability allowing object injection has been identified in the A WP Life Image Gallery plugin, specifically in versions through 1.6.0. This vulnerability could lead to various injection attacks, including code injection, SQL injection, and path traversal, among others, if a suitable property-oriented programming chain is available.

Impact

Exploitation of this vulnerability could allow a malicious actor to inject objects, potentially leading to arbitrary code execution, SQL injection, path traversal, or a denial-of-service condition, depending on the presence of a proper property-oriented programming chain.

Remediation

Users are advised to update to a version later than 1.6.0. For those using Patchstack, a mitigation rule has been issued to block attacks until an official patch is available.

Added: Feb 20, 2026, 7:30 PM
Updated: Feb 20, 2026, 7:30 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.7
remediation
0.0
relevance
3.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.