Object Injection Vulnerability in ThemeGoods Grand Conference
CVE-2025-39354

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 May 2025

What is CVE-2025-39354?

The Grand Conference Theme by ThemeGoods has a deserialization of untrusted data vulnerability that enables object injection. This flaw allows attackers to introduce malicious objects into the application, which can lead to unauthorized actions, code execution, or system compromise. The vulnerability affects all versions of Grand Conference from its initial release up to version 5.2, necessitating immediate attention for website administrators using this theme to ensure their systems are safeguarded against potential exploitation.

Affected Version(s)

Grand Conference <= 5.2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bonds (Patchstack Alliance)
.
CVE-2025-39354 : Object Injection Vulnerability in ThemeGoods Grand Conference