
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3017 is a PHP Object Injection vulnerability in the Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress, affecting all versions up to and including 3.0.12. The flaw was published on April 14, 2026, and stems from unsafe deserialization of untrusted input in the import_shortcodes() function. It carries a CVSS v3.1 base score of 7.2 (High), requiring Administrator-level authentication to exploit (GitHub Advisory, Wordfence).
The root cause is classified as CWE-502 (Deserialization of Untrusted Data): the import_shortcodes() function deserializes user-supplied input without adequate validation, enabling an authenticated administrator to inject arbitrary PHP objects. Exploitation requires network access and Administrator-level credentials, but no user interaction beyond authentication. Critically, no known PHP Object Property (POP) chain exists within the vulnerable plugin itself — impact is contingent on the presence of a POP chain in another installed plugin or theme on the same WordPress site (GitHub Advisory).
If a POP chain is available via another installed plugin or theme, a malicious administrator could leverage the injected PHP object to delete arbitrary files, retrieve sensitive data, or achieve remote code execution on the WordPress server. Without a POP chain present in the environment, the vulnerability has no direct exploitable impact. The affected scope is limited to the WordPress installation itself, but in environments with vulnerable dependencies, the risk extends to full site compromise and potential lateral movement within the hosting environment (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.039–0.047%, placing it in the 15th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is further constrained by the requirement for Administrator-level access and the conditional dependency on a POP chain from a co-installed plugin or theme (GitHub Advisory).
import_shortcodes() function (e.g., via the plugin's import feature in the WordPress admin panel) and supply the crafted serialized payload as the import data.import_shortcodes().curl, wget, reverse shell connections) following an admin import action.Update the Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin to a version newer than 3.0.12, which addresses the unsafe deserialization in import_shortcodes(). A patch is available via the WordPress plugin repository (changeset 3490703) (GitHub Advisory, Plugin Changeset). As interim mitigations: audit all installed plugins and themes for known POP chains and remove unnecessary components; restrict Administrator access to trusted users only; and consider disabling the import feature if not actively required.
Wordfence included CVE-2026-3017 in its weekly WordPress vulnerability report for April 13–19, 2026, noting the PHP Object Injection risk and the conditional nature of its impact (Wordfence Weekly Report). The vulnerability was also noted by RedPacketSecurity on Mastodon and briefly discussed on Bluesky via automated CVE notification accounts, with no significant broader community debate given the limited exploitability without a POP chain.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."