Themes Vulnerabilities

Travel Booking < 2.7.8.6 - Reflected & Persistent XSS Issues

Description

Reflected & Persistent XSS vulnerability was discovered in the 'Travel Booking WordPress Theme', tested version — v2.7.8.5

Edit (WPScanTeam):
January 11th, 2020 - Report received & Envato contacted
January 12th, 2020 - Report updated with Reflected XSS, Envato notified again.
January 12th, 2020 - Envato investigating
January 13th, 2020 - 2.7.8.6 released, fixing the issues

Proof of Concept

Affects Themes

Fixed in 2.7.8.6

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
m0ze
Submitter
m0ze
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2020-01-13 (about 6 years ago)
Added
2020-01-14 (about 6 years ago)
Last Updated
2021-01-19 (about 5 years ago)

Other