Junglewise Threat Intelligence

CVE-2025-69151: ThemeGoods Grand Car Rental unauthenticated XSS

CVE-2025-69151 · Severity: high · CVSS 7.1 · Published 2026-06-17

Vendors: ThemeGoods.

Executive brief

The Grand Car Rental theme for WordPress, used for managing vehicle rental websites, contains a security flaw that allows unauthorized individuals to inject malicious scripts. If a site administrator or visitor clicks a specially crafted link, an attacker could execute code in their browser, potentially leading to unauthorized actions, data theft, or website defacement. As of the latest report, no official patch has been released by the developer.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the ThemeGoods Grand Car Rental theme for WordPress through version 3.7. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted URL. Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser session, which can lead to session hijacking or the performance of unauthorized actions. No official patch is currently available, though third-party mitigation rules have been proposed.

Affected products

  • ThemeGoods Grand Car Rental <= 3.7

Timeline

  • 2025-11-06: other: Vulnerability reported by researcher João Pedro S Alcântara (Kinorth)
  • 2026-05-28: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: CVE published in NVD

References

Related threats