Cyber Posture

CVE-2025-26763

Critical

Published: 22 February 2025

Published
22 February 2025
Modified
23 April 2026
KEV Added
Patch
CVSS Score 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0011 28.8th percentile
Risk Priority 20 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.

Security Summary

CVE-2025-26763 is a Deserialization of Untrusted Data vulnerability (CWE-502) in the MetaSlider Responsive Slider WordPress plugin (ml-slider) that allows Object Injection. This issue affects Responsive Slider by MetaSlider versions from n/a through 3.94.0. The vulnerability was published on 2025-02-22 and carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating critical severity.

Unauthenticated remote attackers can exploit this vulnerability over the network with low attack complexity and no user interaction required. Successful exploitation enables high-impact compromise of confidentiality, integrity, and availability, potentially leading to severe outcomes such as remote code execution via object injection in the PHP-based plugin environment.

The Patchstack advisory at https://patchstack.com/database/Wordpress/Plugin/ml-slider/vulnerability/wordpress-slider-gallery-and-carousel-by-metaslider-image-slider-video-slider-plugin-3-94-0-php-object-injection-vulnerability?_s_id=cve provides further details on the vulnerability, including mitigation recommendations.

Details

CWE(s)
CWE-502

MITRE ATT&CK Enterprise Techniques

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Why these techniques?

The CVE describes an unauthenticated remote deserialization/object injection vulnerability in a public-facing WordPress plugin leading to RCE, directly enabling exploitation of public-facing applications.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

References