Executive brief
The Auto Repair theme for WordPress is vulnerable to a security flaw that allows attackers to run malicious scripts on your website. This typically happens when a site administrator or visitor clicks on a specially crafted link provided by an attacker. If exploited, this could lead to unauthorized actions, theft of session information, or the display of fraudulent content to your customers.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the VamTam Auto Repair theme for WordPress (versions <= 22.6) due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted URL. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized administrative actions. As of the advisory date, no official patch has been released.
Affected products
- VamTam (via WordPress) Auto Repair <= 22.6
Timeline
- 2025-09-17: other: Vulnerability reported by researcher
- 2026-01-13: disclosed: Initial disclosure by Patchstack
- 2026-06-17: advisory: NVD publication date