CVE-2025-39348: WordPress Grand Restaurant WordPress theme <= 7.0 - PHP Object Injection vulnerability
Published May 19, 2025
·Updated
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Restaurant: from n/a through <= 7.0.
Affected Software
2 affected components
ThemeGoods Grand Restaurant<=7.0
ThemeGoods Grand Restaurant WordPress<=7.0
Event History
May 19, 2025
CVE Published
via MITRE·07:52 PM
Data Sourced
via MITRE·07:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-39348?
The severity of CVE-2025-39348 is classified as high due to the potential for object injection attacks.
2
How do I fix CVE-2025-39348?
To fix CVE-2025-39348, update the ThemeGoods Grand Restaurant WordPress theme to version 7.1 or later.
3
What versions are affected by CVE-2025-39348?
CVE-2025-39348 affects all versions of ThemeGoods Grand Restaurant WordPress up to and including version 7.0.
4
What kind of vulnerability is CVE-2025-39348?
CVE-2025-39348 is a deserialization of untrusted data vulnerability that can lead to object injection.
5
Does CVE-2025-39348 affect any other WordPress themes?
CVE-2025-39348 specifically affects the ThemeGoods Grand Restaurant WordPress theme and not other themes.