WordPress Car Repair Services & Auto Mechanic before 4.0 contains a reflected cross-site scripting vulnerability. It does not properly sanitize the serviceestimatekey parameter before outputting it back in the page.
View the template here CVE-2021-24335.yaml
References:
https://themeforest.net/item/car-repair-services-auto-mechanic-wordpress-theme/19823557