Thanks to everyone who contributed updates and context on this. It’s definitely a relief to see that Cryout Creations has rolled out security patches for the XSS vulnerability across their classic themes, including Mantra 3.3.3, Parabola 2.4.2, and Tempera 1.8.3.
For anyone still running older versions, I’d highly recommend updating immediately — especially if your site handles sensitive information or user interactions. Sites in industries like finance or health are often more heavily targeted. In fact, a client I work with, a Health Insurance agency, had similar security concerns and keeping their WordPress themes and plugins updated was essential for compliance and peace of mind.
Website: aversainsurance.com