Object Injection Vulnerability in aThemeArt Translations eDS Responsive Menu
CVE-2025-58839

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 September 2025

What is CVE-2025-58839?

The eDS Responsive Menu plugin from aThemeArt is susceptible to an Object Injection vulnerability due to improper handling of data deserialization. This flaw allows attackers to execute arbitrary code or manipulate the application by injecting untrusted serialized objects, potentially compromising the integrity of the site. Users are encouraged to update to secure versions to mitigate this risk.

Affected Version(s)

eDS Responsive Menu <= 1.2

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mcdruid (Patchstack Alliance)
.
CVE-2025-58839 : Object Injection Vulnerability in aThemeArt Translations eDS Responsive Menu