Impact
The vulnerability is an unauthenticated reflected cross‑site scripting flaw present in the Automotive Car Dealership Business WordPress theme up to version 13.3.3. User input that is reflected back to the page is not properly sanitized, which allows an attacker to embed arbitrary JavaScript whenever the page is accessed with a crafted request. This flaw aligns with CWE‑79, an input validation weakness.
Affected Systems
WordPress sites that have installed the Themesuite Automotive Car Dealership Business theme version 13.3.3 or earlier are affected. No patched release is listed; site owners should verify for an updated package.
Risk and Exploitability
Based on the description, it is inferred that the attack requires a specially crafted URL containing malicious query parameters that the theme reflects back to the victim's browser, allowing arbitrary script execution. CVSS 7.1 indicates a high severity, and the flaw is exploitable without authentication. EPSS < 1%, indicating a very low but nonzero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The vulnerability could be triggered by any user who visits a crafted link, meaning attackers can target visitors through phishing or embedded malicious links.
OpenCVE Enrichment