Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27958 | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Tour | Travel Agency WordPress allows Object Injection. This issue affects Grand Tour | Travel Agency WordPress: from n/a through 5.5.1. |
Thu, 23 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Tour | Travel Agency WordPress allows Object Injection. This issue affects Grand Tour | Travel Agency WordPress: from n/a through 5.5.1. | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Tour grandtour allows Object Injection.This issue affects Grand Tour: from n/a through <= 5.6. |
| Title | WordPress GrandTour Theme <= 5.5.1 - PHP Object Injection vulnerability | WordPress GrandTour theme <= 5.6 - PHP Object Injection vulnerability |
| References | ||
| Metrics |
cvssV3_1
|
Wed, 28 Jan 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Themegoods
Themegoods grand Tour |
|
| CPEs | cpe:2.3:a:themegoods:grand_tour:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Themegoods
Themegoods grand Tour |
Fri, 23 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 23 May 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Tour | Travel Agency WordPress allows Object Injection. This issue affects Grand Tour | Travel Agency WordPress: from n/a through 5.5.1. | |
| Title | WordPress GrandTour Theme <= 5.5.1 - PHP Object Injection vulnerability | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-04-28T16:12:32.633Z
Reserved: 2025-04-16T06:23:51.712Z
Link: CVE-2025-39485
Updated: 2025-05-23T13:37:43.106Z
Status : Modified
Published: 2025-05-23T13:15:30.610
Modified: 2026-04-23T15:29:39.090
Link: CVE-2025-39485
No data.
OpenCVE Enrichment
Updated: 2026-04-30T19:00:14Z
EUVD