Understanding the Threat
A significant security flaw, identified as a Missing Authorization vulnerability, has been found in the ThemeGoods Grand Restaurant WordPress theme. This issue allows attackers to exploit incorrectly configured access control, leading to what is known as Arbitrary Content Deletion. In simple terms, this means an unauthorized individual could potentially delete various types of content from your website, such as images, blog posts, or entire pages, without needing to log in.
CVE Details
This vulnerability impacts the popular Grand Restaurant WordPress theme, specifically versions up to and including 7.0. The official details are:
- Product Name: ThemeGoods Grand Restaurant WordPress Theme
- CVE ID: CVE-2025-39352
- Published Date: May 19, 2025
- Status: Analyzed
Affected Products
The ThemeGoods Grand Restaurant WordPress theme versions through 7.0 are vulnerable to this issue. If you are using any version of this theme up to and including 7.0, your website could be at risk.
Current Status
As of January 22, 2026, this vulnerability is categorized as “Analyzed.” This means the issue has been thoroughly investigated and its impact is understood.
Severity Level
This vulnerability carries a High severity rating with a CVSS score of 8.2. This high score indicates that the flaw is easy to exploit and could lead to serious consequences for affected websites. The primary risk is Arbitrary Content Deletion, meaning malicious actors could remove significant portions of your website’s content.
Possible Solutions
Currently, there is no official patch or updated version available directly from the theme developer to fix this specific vulnerability. However, it is crucial to take immediate action to protect your website.
Security platforms like Patchstack have already implemented mitigation rules to block potential attacks. If you are using a security solution with virtual patching capabilities, ensure it is up to date and actively protecting your site. This acts as a temporary shield until a permanent fix is released by ThemeGoods.
We highly recommend keeping all your WordPress themes and plugins updated. Regularly backing up your website is also a critical step to ensure that even if an attack occurs, you can restore your content quickly.
References
https://patchstack.com/database/wordpress/theme/grandrestaurant/vulnerability/wordpress-grand-restaurant-wordpress-theme-7-0-arbitrary-options-deletion-vulnerability?_s_id=cve


