CVE-2025-39356 Details
Description
Deserialization of Untrusted Data vulnerability in Chimpstudio Foodbakery Sticky Cart foodbakery-sticky-cart allows Object Injection.This issue affects Foodbakery Sticky Cart: from n/a through <= 3.2.
A deserialization vulnerability allowing object injection has been identified in the Chimpstudio Foodbakery Sticky Cart plugin for WordPress, affecting versions through 3.2. This vulnerability arises from the improper handling of untrusted data, which could potentially be exploited to execute arbitrary code, inject malicious SQL, traverse file paths, cause denial-of-service conditions, and more, provided a suitable object injection chain is available.
Users are advised to update to a version of the Foodbakery Sticky Cart plugin for WordPress that is later than 3.2. For those unable to update immediately, Patchstack offers a virtual patch that blocks attacks targeting this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 19, 2025CISA-ADP
Assessed May 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Chimpstudio Foodbakery Sticky Cart | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2026 | CVE Modified | [email protected] |
| Apr 1, 2026 | CVE Modified | [email protected] |
| May 19, 2025 | New CVE Received | [email protected] |
Volerion