Security Advisory

CVE-2021-24297

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2021-05-24 10:58:04
Last updated 2024-08-03 19:28:23
Assigner WPScan
CVSS score not scored
State PUBLISHED

Description

The Goto WordPress theme before 2.1 did not properly sanitize the formvalue JSON POST parameter in its tl_filter AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability.