Executive brief
The Automotive Car Dealership Business theme for WordPress is vulnerable to a security flaw that allows users with low-level account access to inject malicious scripts into the website. This theme is used by car dealerships to manage inventory and portfolio items. If exploited, an attacker could hijack administrative sessions or redirect visitors to malicious websites, potentially damaging the dealership's reputation and compromising customer data.
Technical details
The Automotive Car Dealership Business WordPress Theme (up to version 13.4.1) contains a Stored Cross-Site Scripting (XSS) vulnerability. The root cause is insufficient input sanitization and output escaping within the 'project_details' custom field used in Portfolio Items. An authenticated attacker with contributor-level permissions or higher can inject malicious JavaScript into this field. Because the script is stored in the database and executed in the context of any user (including administrators) who views the affected page, it can lead to session hijacking or unauthorized actions. The vulnerability is tracked as CVE-2025-14042.
Affected products
- Themesuite Automotive Car Dealership Business WordPress Theme Up to, and including, 13.4.1
Timeline
- 2026-05-29: disclosed: Initial public disclosure and NVD publication