Deserialization of Untrusted Data in ThemeGoods Grand Tour WordPress Plugin
CVE-2025-39485
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 May 2025
What is CVE-2025-39485?
A vulnerability exists in the ThemeGoods Grand Tour plugin for WordPress due to a deserialization of untrusted data. This flaw allows for object injection, which could potentially lead to the execution of arbitrary code. Affected versions include all versions up to and including 5.5.1. Users are advised to update to the latest version to mitigate the risks associated with this vulnerability.
Affected Version(s)
Grand Tour | Travel Agency WordPress <= 5.5.1
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Bonds (Patchstack Alliance)