Deserialization of Untrusted Data Vulnerability in ThemeMakers Car Dealer
CVE-2025-39480
9.8CRITICAL
What is CVE-2025-39480?
A deserialization of untrusted data vulnerability in ThemeMakers Car Dealer allows for object injection, which could potentially lead to unauthorized access or manipulation of sensitive data. This affects all versions starting from n/a up to 1.6.6, prompting users to ensure their WordPress installations are secure and regularly updated. It's critical for developers to implement proper sanitization and validation of input data to mitigate potential exploitation.
Affected Version(s)
Car Dealer <= 1.6.6