WordPress Goto Tour & Travel theme before 2.0 contains an unauthenticated reflected cross-site scripting vulnerability. It does not sanitize the keywords and start_date GET parameters on its Tour List page.
id: CVE-2021-24235
info:
name: WordPress Goto Tour & Travel Theme <2.0 - Cross-Site Scripting
a
...