Car Repair Services & Auto Mechanic WordPress Theme + RTL [car-repair-services] <= 5.0 (unfixed)
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Car Repair Services allows Server Side Request Forgery. This issue affects Car Repair Services: from n/a through 5.0.
- Affected:
- up to 5.0
- Fix:
- No patched version reported
- Disclosed:
- Jun 6, 2025
CVE-2025-30997 on NVD →
Car Repair Services <= 5.0 - Unauthenticated Server-Side Request Forgery
high
The Car Repair Services theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application which can be used to query and modify information from...
- CVSS:
- 7.2
- Affected:
- up to 5.0
- Fix:
- No patched version reported
- Disclosed:
- Jun 5, 2025
CVE-2025-30997 on NVD →
Car Repair Services & Auto Mechanic WordPress Theme + RTL [car-repair-services] < 4.0
unknown
[en] The Car Repair Services & Auto Mechanic WordPress theme before 4.0 did not properly sanitise its serviceestimatekey search parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting issue
- Affected:
- up to 4.0
- Fixed in:
- 4.0
- Disclosed:
- Jun 1, 2021
CVE-2021-24335 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database