CVE-2025-39354: WordPress Grand Conference theme <= 5.3 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Conference grandconference allows Object Injection.This issue affects Grand Conference: from n/a through <= 5.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39354?
CVE-2025-39354 is classified as a critical vulnerability due to its potential for object injection via deserialization of untrusted data.
How do I fix CVE-2025-39354?
To fix CVE-2025-39354, update the ThemeGoods Grand Conference to version 5.3 or later where the vulnerability is addressed.
What versions are affected by CVE-2025-39354?
CVE-2025-39354 affects all versions of ThemeGoods Grand Conference up to and including version 5.2.
What type of vulnerability is CVE-2025-39354?
CVE-2025-39354 is a deserialization of untrusted data vulnerability that can lead to object injection.
Who is impacted by CVE-2025-39354?
Users of ThemeGoods Grand Conference and WordPress Grand Conference versions up to 5.2 are impacted by CVE-2025-39354.