Impact
The CarDealerPress plugin for WordPress contains a stored XSS flaw that allows an attacker with Contributor or higher privileges to inject arbitrary scripts via the saleclass parameter. The input is not properly sanitized or escaped before being saved, so the malicious payload is rendered unmodified when users visit an affected page, resulting in the execution of arbitrary scripts in the context of the site.
Affected Systems
All installations of the dealertrend:CarDealerPress plugin in versions 6.8.2505.00 and earlier are affected. The vulnerability exists in the plugin code that processes the saleclass field used in inventory shortcodes.
Risk and Exploitability
The CVSS score of 6.4 reflects a moderate severity stored XSS flaw. The EPSS score of less than 1% indicates a very low likelihood of public exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires authenticated access with Contributor or higher privileges, an attacker can inject scripts that run for any site user who views the affected content, potentially enabling script‑based attacks on site visitors.
OpenCVE Enrichment
EUVD