rootpwn

critical · CVSS v3 8.8

CVE-2026-97284

Icegram versions up to 3.1.31 contain a PHP Object Injection vulnerability accessible to users with Contributor privileges. The flaw may all

Overview

Icegram versions up to 3.1.31 contain a PHP Object Injection vulnerability accessible to users with Contributor privileges. The flaw may allow manipulation of serialized PHP objects, which can lead to unauthorized actions or code execution depending on available application gadgets. It matters because WordPress sites with Icegram installed and low-privilege contributor accounts may be exposed.

Description

Contributor PHP Object Injection in Icegram <= 3.1.31 versions.

Impact

Confidentiality, integrity, and availability can be affected if an attacker with Contributor access can trigger unsafe object deserialization. Impacted systems are WordPress deployments running Icegram at or below 3.1.31, especially those with multiple contributors or external content submitters. Successful exploitation could lead to data disclosure, defacement, or site compromise. The risk is elevated when the site has other vulnerable plugins or themes that provide exploitable gadget chains.

Remediation

Update Icegram to the latest vendor-released version above 3.1.31 as soon as available. If no update is available, disable or remove Icegram until a fix is confirmed. Restrict Contributor access to trusted users only and review recent contributor accounts, posts, comments, and media uploads for anomalies. Apply WAF rules to block suspicious serialized PHP payloads and monitor web server/application logs for deserialization-related errors or unexpected admin actions.

Risk context

CVSS v3 8.8 indicates a high/critical severity issue, and the critical label warrants prompt defensive action. No EPSS score is provided, so exploit likelihood cannot be quantified from the supplied data. Treat as urgent for internet-facing WordPress sites with Icegram installed and contributor accounts enabled.

Affected products

  • Icegram <= 3.1.31
  • WordPress plugin Icegram

Scores

Severity
critical
CVSS v2
9
CVSS v3
8.8
CVSS v4
—
EPSS
—

php-object-injection wordpress-plugin icegram contributor-access deserialization cve-2026-97284

← All CVEs