CVE-2025-39356: WordPress Foodbakery Sticky Cart plugin <= 3.2 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in Chimpstudio Foodbakery Sticky Cart allows Object Injection.This issue affects Foodbakery Sticky Cart: from n/a through 3.2.
Other sources
Deserialization of Untrusted Data vulnerability in Chimpstudio Foodbakery Sticky Cart foodbakery-sticky-cart allows Object Injection.This issue affects Foodbakery Sticky Cart: from n/a through <= 3.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39356?
CVE-2025-39356 is classified as a high-severity vulnerability due to its potential for object injection.
How do I fix CVE-2025-39356?
To fix CVE-2025-39356, users should upgrade the Foodbakery Sticky Cart plugin to the latest version beyond 3.2.
What products are affected by CVE-2025-39356?
CVE-2025-39356 affects the Foodbakery Sticky Cart plugin for WordPress versions up to and including 3.2.
What type of vulnerability is CVE-2025-39356?
CVE-2025-39356 is a deserialization of untrusted data vulnerability that allows object injection.
Is CVE-2025-39356 being actively exploited?
While there is no specific information about active exploitation of CVE-2025-39356, the nature of the vulnerability poses significant security risks.