Description
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Restaurant: from n/a through <= 7.0.
Published: 2025-05-19
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a flaw in the Grand Restaurant WordPress theme that permits untrusted data deserialization, enabling an attacker to inject PHP objects into the application. This object injection can lead to arbitrary code execution, compromising the confidentiality, integrity, and availability of the site and potentially the underlying server. The flaw is categorized as CWE‑502, which is known for enabling remote code execution when an application accepts serialized data from outside sources.

Affected Systems

The exposed product is the Grand Restaurant theme released by ThemeGoods. All releases from the initial version through and including version 7.0 are affected. The exact starting version is not listed, but any installation of the theme with a version number <= 7.0 is vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.8, classifying it as critical. The EPSS score is less than 1%, indicating a very low but nonzero probability of exploitation in the wild, and it is not listed in the CISA KEV catalog. The likely attack vector is remote; an attacker can craft a malicious request that includes serialized data processed by the theme, such as through a file upload, custom shortcode, or query parameter that the theme deserializes. Given the severity of the flaw and the potential for remote code execution, systems running the affected theme should treat the risk as high, even if actual exploitation probability is currently low.

Generated by OpenCVE AI on April 30, 2026 at 19:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Grand Restaurant theme to the latest version that contains the deserialization fix.
  • If an updated theme is unavailable, deactivate or replace the theme with a different, trusted theme while awaiting a patch.
  • Restrict role permissions that allow users to supply input processed by the theme, and enforce strict validation on any data the theme deserializes.
  • Monitor WordPress security advisories and apply any new patches or updates promptly.

Generated by OpenCVE AI on April 30, 2026 at 19:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-15785 Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant WordPress allows Object Injection.This issue affects Grand Restaurant WordPress: from n/a through 7.0.
History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant WordPress allows Object Injection.This issue affects Grand Restaurant WordPress: from n/a through 7.0. Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Object Injection.This issue affects Grand Restaurant: from n/a through <= 7.0.
References

Thu, 29 May 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Themegoods
Themegoods grand Restaurant
CPEs cpe:2.3:a:themegoods:grand_restaurant:*:*:*:*:*:wordpress:*:*
Vendors & Products Themegoods
Themegoods grand Restaurant

Mon, 19 May 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 19 May 2025 20:00:00 +0000

Type Values Removed Values Added
Description Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Restaurant WordPress allows Object Injection.This issue affects Grand Restaurant WordPress: from n/a through 7.0.
Title WordPress Grand Restaurant WordPress theme <= 7.0 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Themegoods Grand Restaurant
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:29.130Z

Reserved: 2025-04-16T06:22:10.074Z

Link: CVE-2025-39348

cve-icon Vulnrichment

Updated: 2025-05-19T21:11:05.006Z

cve-icon NVD

Status : Modified

Published: 2025-05-19T20:15:22.740

Modified: 2026-04-23T15:29:23.240

Link: CVE-2025-39348

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T19:30:26Z

Weaknesses