CVE-2025-67922: WordPress Grand Restaurant theme < 7.0.9 - Cross Site Scripting (XSS) vulnerability
Published Jan 8, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Reflected XSS.This issue affects Grand Restaurant: from n/a through < 7.0.9.
Affected Software
2 affected components
ThemeGoods Grand Restaurant<7.0.9
ThemeGoods Grand Restaurant WordPress<7.0.9
Event History
Jan 8, 2026
CVE Published
via MITRE·09:17 AM
Data Sourced
via MITRE·09:17 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Nov 14, 58279
Event
via MITRE·03:58 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-67922?
CVE-2025-67922 is classified as a high-severity reflected cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2025-67922?
To fix CVE-2025-67922, update the ThemeGoods Grand Restaurant plugin to version 7.0.9 or later.
3
What versions of Grand Restaurant are affected by CVE-2025-67922?
CVE-2025-67922 affects all versions of Grand Restaurant prior to version 7.0.9.
4
What type of attack does CVE-2025-67922 enable?
CVE-2025-67922 enables reflected cross-site scripting (XSS) attacks, allowing an attacker to inject malicious scripts.
5
Which vendor is associated with CVE-2025-67922?
The vendor associated with CVE-2025-67922 is ThemeGoods, specifically for their Grand Restaurant theme.