Junglewise Threat Intelligence

CVE-2026-27425: Themesuite Automotive Listings unauthenticated XSS

CVE-2026-27425 · Severity: high · CVSS 7.1 · Published 2026-07-02

Executive brief

The Automotive Listings plugin for WordPress, used to manage vehicle inventories on websites, contains a security flaw that allows attackers to inject malicious scripts. By tricking a site visitor or administrator into clicking a specially crafted link, an attacker could execute code in their browser to steal session information or redirect them to malicious websites. At the time of this report, no official patch has been released by the developer.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in the Themesuite Automotive Listings plugin for WordPress through version 18.6. The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by sending a crafted URL to a victim; if the victim interacts with the link, the attacker's script executes within the context of the victim's browser session. This can lead to session hijacking or unauthorized actions performed on behalf of the user. As of the advisory date, no official patch is available, though third-party mitigation rules have been proposed.

Affected products

  • Themesuite Automotive Listings <= 18.6

Timeline

  • 2025-10-20: other: Vulnerability reported by researcher João Pedro S Alcântara
  • 2026-06-29: advisory: Initial advisory published by Patchstack
  • 2026-07-02: disclosed: CVE published to NVD dataset

References