Record summary

CVE-2021-24235 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs and 1 Nuclei template.

Description

The Goto WordPress theme before 2.0 does not sanitise the keywords and start_date GET parameter on its Tour List page, leading to an unauthenticated reflected Cross-Site Scripting issue.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
2
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Goto

CVE List2.0 to < 2.0affected

Proofs of concept

2

Curated repository PoCs

GitHubCVE-2021-24235Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file

Python · 642 B

GitHub

PoC details
GitHubCVE-2021-24235Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 642 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Goto Tour & Travel Theme <2.0 - Cross-Site ScriptingCVSS 6.1

WordPress Goto Tour & Travel theme before 2.0 contains an unauthenticated reflected cross-site scripting vulnerability. It does not sanitize the keywords and start_date GET parameters on its Tour List page.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the website, leading to potential data theft, session hijacking, or defacement.

Remediation

Update to the latest version of the WordPress Goto Tour & Travel Theme (>=2.0) to mitigate the XSS vulnerability.

WeaknessesCWE-79
Authorsdaffainfo
Template tagscve2021cvexsswp-themewpscanwordpressboostifythemesvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:boostifythemes:goto:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

4