WordPress Goto Tour & Travel Theme <2.0 - Cross-Site Scripting
WordPress Goto Tour & Travel theme before 2.0 contains an unauthenticated reflected cross-site scripting vulnerability. It does not sanitize the keywords and start_date GET parameters on its Tour List page.
gotoPoC 已收录
CVSS6.1EPSS 26.7%