Impact
CVE-2025-39353 exposes a Missing Authorization flaw in the Grand Restaurant WordPress theme, allowing attackers to bypass access controls on privileged pages and functions. The vulnerability is rooted in improper permission checks and is classified as CWE‑862. Attackers who exploit this flaw can potentially read, modify, or delete content and settings that should be restricted to authenticated administrators, thereby compromising confidentiality, integrity, and availability within the affected WordPress site.
Affected Systems
The vulnerability affects ThemeGoods' Grand Restaurant theme versions that are 7.0 and earlier. Users running these themes on any WordPress installation are at risk. Updating the theme beyond version 7.0 eliminates the flaw.
Risk and Exploitability
The CVSS score of 5.3 reflects a medium severity, while the EPSS score of less than 1% indicates a low likelihood of widespread exploitation. The issue is currently not listed in the CISA KEV catalog. Based on the description, the attack vector is most likely web‑based, involving crafted HTTP requests to administrative or hidden endpoints that lack proper access checks. Successful exploitation would require an attacker to send requests to these endpoints and observe responses that confirm unauthorized privileges.
OpenCVE Enrichment
EUVD