Impact
The Grand Restaurant theme for WordPress contains an improper neutralization of input during web page generation, allowing reflected cross‑site scripting. An attacker can inject malicious script into the page that is rendered to the victim’s browser, potentially stealing session cookies, hijacking user accounts, or defacing the site. This flaw is a classic reflected XSS scenario and could be leveraged to execute arbitrary code within the victim’s browser context.
Affected Systems
The vulnerability affects all installations of the ThemeGoods Grand Restaurant theme earlier than version 7.0.11. Users running the theme on WordPress sites without the latest patch are exposed to this security risk.
Risk and Exploitability
The CVSS score of 7.1 classifies this flaw as high severity, yet the EPSS score is not available, indicating limited publicly available exploitation data. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation at the time of analysis. Attackers could exploit the flaw through crafted URLs or search query parameters without requiring authentication, making the risk tangible for any public WordPress deployment using this theme.
OpenCVE Enrichment