CVE-2025-39485: WordPress GrandTour theme <= 5.6 - PHP Object Injection vulnerability
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Tour grandtour allows Object Injection.This issue affects Grand Tour: from n/a through <= 5.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39485?
CVE-2025-39485 has a medium severity level due to the potential for object injection leading to unauthorized code execution.
How do I fix CVE-2025-39485?
To fix CVE-2025-39485, upgrade to the latest version of Grand Tour | Travel Agency WordPress that is beyond 5.5.1.
What types of attacks can exploit CVE-2025-39485?
CVE-2025-39485 can be exploited through deserialization of untrusted data, potentially allowing attackers to inject malicious objects.
Which versions of Grand Tour | Travel Agency WordPress are affected by CVE-2025-39485?
CVE-2025-39485 affects all versions of Grand Tour | Travel Agency WordPress from n/a through 5.5.1.
Is CVE-2025-39485 a common vulnerability in WordPress themes?
While not as common as some vulnerabilities, CVE-2025-39485 highlights a critical risk in improper data deserialization in WordPress themes.