WordPress Car Repair Services & Auto Mechanic before 4.0 contains a reflected cross-site scripting vulnerability. It does not properly sanitize the serviceestimatekey parameter before outputting it back in the page.
id: CVE-2021-24335
info:
name: WordPress Car Repair Services & Auto Mechanic Theme <4.0 - Cross-S
...