Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Reflected XSS.This issue affects Grand Restaurant: from n/a before 7.0.11.
Published: 2026-10-09
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting
Action: Patch Now
AI Analysis

Impact

The Grand Restaurant theme for WordPress contains an improper neutralization of input during web page generation, allowing reflected cross‑site scripting. An attacker can inject malicious script into the page that is rendered to the victim’s browser, potentially stealing session cookies, hijacking user accounts, or defacing the site. This flaw is a classic reflected XSS scenario and could be leveraged to execute arbitrary code within the victim’s browser context.

Affected Systems

The vulnerability affects all installations of the ThemeGoods Grand Restaurant theme earlier than version 7.0.11. Users running the theme on WordPress sites without the latest patch are exposed to this security risk.

Risk and Exploitability

The CVSS score of 7.1 classifies this flaw as high severity, yet the EPSS score is not available, indicating limited publicly available exploitation data. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation at the time of analysis. Attackers could exploit the flaw through crafted URLs or search query parameters without requiring authentication, making the risk tangible for any public WordPress deployment using this theme.

Generated by OpenCVE AI on October 9, 2026 at 11:27 UTC.

Remediation

Vendor Solution

Update the WordPress Grand Restaurant theme to the latest available version (at least 7.0.11).


OpenCVE Recommended Actions

  • Update the Grand Restaurant theme to version 7.0.11 or newer, which removes the reflected XSS flaw.
  • If immediate update is not feasible, implement a web application firewall rule or input sanitization filter to block or escape suspicious script payloads in query parameters.
  • Regularly audit installed WordPress themes and plugins for known vulnerabilities, and subscribe to ThemeGoods security advisories for future patches.

Generated by OpenCVE AI on October 9, 2026 at 11:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Reflected XSS.This issue affects Grand Restaurant: from n/a before 7.0.11.
Title WordPress Grand Restaurant theme < 7.0.11 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-09T10:00:35.885Z

Reserved: 2026-09-21T00:20:20.797Z

Link: CVE-2026-94161

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T10:16:39.923

Modified: 2026-10-09T10:16:39.923

Link: CVE-2026-94161

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T11:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')