Junglewise Threat Intelligence

CVE-2026-27426: Themesuite Automotive Car Dealership Business unauthenticated XSS

CVE-2026-27426 · Severity: high · CVSS 7.1 · Published 2026-07-02

Executive brief

The Automotive Car Dealership Business theme for WordPress is vulnerable to a security flaw that allows attackers to run malicious scripts on the site. This theme is used by car dealerships to manage vehicle listings and business operations. If exploited, an attacker could redirect visitors to malicious websites, steal session information, or deface the site, potentially damaging the dealership's reputation and customer trust.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in the Themesuite Automotive Car Dealership Business theme for WordPress (versions <= 13.3.3) due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a specially crafted link. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, which can lead to session hijacking or unauthorized actions. As of the advisory date, no official patch has been released, though third-party mitigation rules are available.

Affected products

  • Themesuite Automotive Car Dealership Business <= 13.3.3

Timeline

  • 2025-10-20: other: Vulnerability reported by researcher João Pedro S Alcântara (Kinorth)
  • 2026-06-30: advisory: Patchstack published advisory details
  • 2026-07-02: disclosed: CVE published to NVD dataset

References

Related threats