
🚨 CVE-2025-39480: WordPress Car Dealer theme < 1.6... PHP object injection in WordPress Car Dealer theme with 9.8 CVSS - unauthenticated RCE via deserialization, perfect for... https://zerodaysignal.com/vulnerability/CVE-2025-39480 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The tweet announces CVE-2025-39480, a PHP object injection flaw in WordPress Car Dealer themes under 1.6 that permits unauthenticated remote code execution via deserialization, with a 9.8 CVSS score.
