Impact
The theme incorporates an unauthenticated reflected XSS flaw in all versions up to and including 13.3.3. User‑supplied query parameters are echoed back without proper sanitization, allowing an attacker to inject arbitrary JavaScript into a victim’s browser. This client‑side vulnerability can be triggered by any user visiting a crafted link and is classified as CWE‑79.
Affected Systems
WordPress installations that have installed the Themesuite Automotive Car Dealership Business theme version 13.3.3 or earlier are affected. Site owners should replace the vulnerable theme with any version newer than 13.3.3 when a release becomes available.
Risk and Exploitability
An attacker can trigger the vulnerability by crafting a URL containing malicious query parameters that the theme reflects back to the victim’s browser, allowing execution of arbitrary JavaScript. The CVSS score of 7.1 indicates high severity for this unauthenticated, client‑side flaw. The EPSS score of less than 1% suggests a very low but nonzero likelihood of exploitation. The flaw is not listed in the CISA KEV catalog.
OpenCVE Enrichment