Grand Restaurant WordPress Theme Arbitrary Content Deletion Vulnerability (CVE-2025-39352) — High Severity

Understanding the Threat

A significant security flaw, identified as a Missing Authorization vulnerability, has been found in the ThemeGoods Grand Restaurant WordPress theme. This issue allows attackers to exploit incorrectly configured access control, leading to what is known as Arbitrary Content Deletion. In simple terms, this means an unauthorized individual could potentially delete various types of content from your website, such as images, blog posts, or entire pages, without needing to log in.

CVE Details

This vulnerability impacts the popular Grand Restaurant WordPress theme, specifically versions up to and including 7.0. The official details are:

  • Product Name: ThemeGoods Grand Restaurant WordPress Theme
  • CVE ID: CVE-2025-39352
  • Published Date: May 19, 2025
  • Status: Analyzed

Affected Products

The ThemeGoods Grand Restaurant WordPress theme versions through 7.0 are vulnerable to this issue. If you are using any version of this theme up to and including 7.0, your website could be at risk.

Current Status

As of January 22, 2026, this vulnerability is categorized as “Analyzed.” This means the issue has been thoroughly investigated and its impact is understood.

Severity Level

This vulnerability carries a High severity rating with a CVSS score of 8.2. This high score indicates that the flaw is easy to exploit and could lead to serious consequences for affected websites. The primary risk is Arbitrary Content Deletion, meaning malicious actors could remove significant portions of your website’s content.

Possible Solutions

Currently, there is no official patch or updated version available directly from the theme developer to fix this specific vulnerability. However, it is crucial to take immediate action to protect your website.

Security platforms like Patchstack have already implemented mitigation rules to block potential attacks. If you are using a security solution with virtual patching capabilities, ensure it is up to date and actively protecting your site. This acts as a temporary shield until a permanent fix is released by ThemeGoods.

We highly recommend keeping all your WordPress themes and plugins updated. Regularly backing up your website is also a critical step to ensure that even if an attack occurs, you can restore your content quickly.

References

https://patchstack.com/database/wordpress/theme/grandrestaurant/vulnerability/wordpress-grand-restaurant-wordpress-theme-7-0-arbitrary-options-deletion-vulnerability?_s_id=cve

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.