Input validation vulnerability in Goto – Tour & Travel WordPress Theme 2.0

The Goto WordPress theme before version 2.0 had a problem with its Tour List page. It did not filter out potentially unsafe words or dates that someone might enter in the search box. This allowed malicious code to be entered and spread when people used the search box. This was a security issue known as Cross-Site Scripting.

Detected in:

Goto - Tour & Travel WordPress Theme fixed vulnerable versions: >= * < 2.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.