CVE Details
Basic Information
| Title | CVE-2025-39356 |
|---|---|
| Type | cve |
| Published | 2025-05-19T20:15:23 |
| Last Seen | 2025-05-19T20:23:58 |
CVSS Information
| Base Score | 9.8 (CRITICAL) |
|---|---|
| Attack Vector | NETWORK |
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AI Analysis
| AI Description | A critical deserialization vulnerability in Chimpstudio Foodbakery Sticky Cart allows attackers to inject malicious objects, potentially leading to remote code execution. This issue is easily exploitable without user interaction, affecting confidentiality, integrity, and availability. |
|---|---|
| AI Severity | Critical |
| Vendor | WordPress Community |
| Product | Chimpstudio Foodbakery Sticky Cart |
| Affected Version | n/a |
Additional Information
| CVE List | CVE-2025-39356 |
|---|---|
| CWE List | CWE-502 |
| Bulletin Family | cve |
Description
Deserialization of Untrusted Data vulnerability in Chimpstudio Foodbakery Sticky Cart allows Object Injection. This issue affects Foodbakery Sticky Cart: from n/a through…
CVSS Score Summary
Base Score: %!f(string=#) (CRITICAL)