Sceawere
Vulnerability Detail
CVE-2026-94161UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Reflected XSS in Grand Restaurant
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- ThemeGoods
- Product
- Grand Restaurant
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Reflected XSS.This issue affects Grand Restaurant: from n/a before 7.0.11.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-09T10:16:39.923Z",
"pubdate": "2026-10-09T10:16:39.923Z",
"executiveSummary": "The Grand Restaurant theme for WordPress is susceptible to a Reflected Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation.\nThis vulnerability allows an unauthenticated, remote attacker to inject malicious client-side scripts into the application's responses.\nWhen a victim visits a specially crafted URL, the malicious payload is executed within the context of the user's browser session.\nThe vulnerability affects Grand Restaurant versions prior to 7.0.11.\nSuccessful exploitation can lead to unauthorized actions performed on behalf of the victim, session hijacking, credential theft, or the redirection of users to malicious third-party websites.\nThe impact is categorized as significant because it undermines the integrity of the user's interaction with the web application and facilitates client-side attacks.",
"technicalDetails": "The vulnerability is an Improper Neutralization of Input During Web Page Generation, classified as a Reflected Cross-Site Scripting (XSS) flaw. It exists because the Grand Restaurant theme fails to perform adequate sanitization or output encoding on user-controllable input parameters before reflecting them back to the end-user's browser in an HTTP response.\nThe exploitation flow begins with an attacker identifying an input parameter—typically passed via a GET request—that is unsafely rendered in the application's HTML output. By crafting a URL containing a malicious JavaScript payload in this parameter, the attacker can manipulate the Document Object Model (DOM) of the page when the victim accesses the link.\nBecause the input is not properly encoded or escaped, the victim's browser interprets the injected script tags as legitimate site content rather than data, leading to the execution of the arbitrary JavaScript. This occurs entirely on the client side.\nThe attack is characterized as 'reflected' because the payload is not stored persistently on the server but is instead delivered through the victim's interaction with a malicious link. No authentication or specific privilege level is required to initiate the attack, as it relies on the victim triggering the reflected payload while logged into or interacting with the vulnerable WordPress site.\nPost-exploitation, the attacker may perform various unauthorized activities, such as extracting session cookies (if 'HttpOnly' flags are not present), capturing sensitive information displayed on the page, or using the victim's current authenticated session to perform actions on the WordPress dashboard. Furthermore, the attacker can modify the visual representation of the site to conduct phishing attacks against the victim, thereby expanding the potential scope of the compromise beyond simple script execution."
}