theme

Lovetravel Vulnerabilities

8 known security issues reported for the Lovetravel WordPress theme. Most recent disclosed Nov 12, 2020.

2 medium

Running Lovetravel on your site? Check whether your installed version is affected.

Scan your site free

Love Travel [lovetravel] < 3.9

unknown

Unauthenticated Reflected Cross-Site Scripting (XSS) and Cross-Frame Scripting (XFS) vulnerabilities found by Ex.Mi in WordPress Love Travel premium theme (versions <= 3.8).

Affected:
up to 3.9
Fixed in:
3.9
Disclosed:
Nov 12, 2020

Love Travel 1.0 - 1.9 - Reflected Cross-Site Scripting and Cross-Frame Scripting

medium

The Love Travel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting and Cross-Frame Scripting via the 'nd_travel_archive_form_keyword' and 'nd_travel_typology_slug' parameters in versions up to, and including, 1.0 - 1.9 due to insufficient input sanitization and output escaping. This makes it possible...

CVSS:
6.1
Affected:
1.0 – 1.9
Fixed in:
2.0
Disclosed:
Sep 9, 2020

Love Travel 2.0 - 3.7 - Reflected Cross-Site Scripting

medium

The Love Travel theme for WordPress is vulnerable to Reflected Cross-Site Scripting and Cross-Frame Scripting via the 'keyword', 'date_from', 'date_to', 'price_from_to', 'nicdark_price_from', and 'nicdark_price_to' parameters in versions 2.0 - 3.7 due to insufficient input sanitization and output escaping. This makes i...

CVSS:
6.1
Affected:
2.0 – 3.7
Fixed in:
3.8
Disclosed:
Sep 9, 2020

Love Travel [lovetravel] < 2.0

unknown

Unauthenticated Reflected Cross-Site Scripting (XSS) and Cross-Frame Scripting (XFS) vulnerabilities found by Ex.Mi in WordPress Love Travel premium theme (versions <= 1.9)

Affected:
up to 2.0
Fixed in:
2.0
Disclosed:
Sep 9, 2020

Love Travel [lovetravel] >= 1.0 - <= 1.9

unknown

The Love Travel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting and Cross-Frame Scripting via the 'nd_travel_archive_form_keyword' and 'nd_travel_typology_slug' parameters in versions up to, and including, 1.0 - 1.9 due to insufficient input sanitization and output escaping. This makes it possible...

Affected:
1.0 – 1.9
Fixed in:
1.9
Disclosed:
Sep 9, 2020

Love Travel [lovetravel] >= 2.0 - <= 3.8 (unfixed)

unknown

The Love Travel theme for WordPress is vulnerable to Reflected Cross-Site Scripting and Cross-Frame Scripting via the 'keyword', 'date_from', 'date_to', 'price_from_to', 'nicdark_price_from', and 'nicdark_price_to' parameters in versions 2.0 - 3.8 due to insufficient input sanitization and output escaping. This makes i...

Affected:
2.0 – 3.8
Fix:
No patched version reported
Disclosed:
Sep 9, 2020

Love Travel [lovetravel] >= 2.0 - <= 3.8 (unfixed)

unknown

An Unauthenticated Reflected XSS &amp; XFS vulnerabilities was discovered in the Love Travel theme for WordPress, affected versions: 2.0-3.8. Vulnerable parameters: keyword, date_from, date_to, price_from_to, nicdark_price_from, nicdark_price_to

Affected:
2.0 – 3.8
Fix:
No patched version reported

Love Travel [lovetravel] < 2.0

unknown

An Unauthenticated Reflected XSS &amp; XFS vulnerabilities was discovered in the Love Travel theme for WordPress, affected versions: 1.0-1.9. Vulnerable parameters: nd_travel_archive_form_keyword, nd_travel_typology_slug. The issue was fixed due to a code rewrite of the theme.

Affected:
up to 2.0
Fixed in:
2.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database