Love Travel [lovetravel] < 3.9
unknown
Unauthenticated Reflected Cross-Site Scripting (XSS) and Cross-Frame Scripting (XFS) vulnerabilities found by Ex.Mi in WordPress Love Travel premium theme (versions <= 3.8).
- Affected:
- up to 3.9
- Fixed in:
- 3.9
- Disclosed:
- Nov 12, 2020
Love Travel 1.0 - 1.9 - Reflected Cross-Site Scripting and Cross-Frame Scripting
medium
The Love Travel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting and Cross-Frame Scripting via the 'nd_travel_archive_form_keyword' and 'nd_travel_typology_slug' parameters in versions up to, and including, 1.0 - 1.9 due to insufficient input sanitization and output escaping. This makes it possible...
- CVSS:
- 6.1
- Affected:
- 1.0 – 1.9
- Fixed in:
- 2.0
- Disclosed:
- Sep 9, 2020
Love Travel 2.0 - 3.7 - Reflected Cross-Site Scripting
medium
The Love Travel theme for WordPress is vulnerable to Reflected Cross-Site Scripting and Cross-Frame Scripting via the 'keyword', 'date_from', 'date_to', 'price_from_to', 'nicdark_price_from', and 'nicdark_price_to' parameters in versions 2.0 - 3.7 due to insufficient input sanitization and output escaping. This makes i...
- CVSS:
- 6.1
- Affected:
- 2.0 – 3.7
- Fixed in:
- 3.8
- Disclosed:
- Sep 9, 2020
Love Travel [lovetravel] < 2.0
unknown
Unauthenticated Reflected Cross-Site Scripting (XSS) and Cross-Frame Scripting (XFS) vulnerabilities found by Ex.Mi in WordPress Love Travel premium theme (versions <= 1.9)
- Affected:
- up to 2.0
- Fixed in:
- 2.0
- Disclosed:
- Sep 9, 2020
Love Travel [lovetravel] >= 1.0 - <= 1.9
unknown
The Love Travel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting and Cross-Frame Scripting via the 'nd_travel_archive_form_keyword' and 'nd_travel_typology_slug' parameters in versions up to, and including, 1.0 - 1.9 due to insufficient input sanitization and output escaping. This makes it possible...
- Affected:
- 1.0 – 1.9
- Fixed in:
- 1.9
- Disclosed:
- Sep 9, 2020
Love Travel [lovetravel] >= 2.0 - <= 3.8 (unfixed)
unknown
The Love Travel theme for WordPress is vulnerable to Reflected Cross-Site Scripting and Cross-Frame Scripting via the 'keyword', 'date_from', 'date_to', 'price_from_to', 'nicdark_price_from', and 'nicdark_price_to' parameters in versions 2.0 - 3.8 due to insufficient input sanitization and output escaping. This makes i...
- Affected:
- 2.0 – 3.8
- Fix:
- No patched version reported
- Disclosed:
- Sep 9, 2020
Love Travel [lovetravel] >= 2.0 - <= 3.8 (unfixed)
unknown
An Unauthenticated Reflected XSS & XFS vulnerabilities was discovered in the Love Travel theme for WordPress, affected versions: 2.0-3.8. Vulnerable parameters: keyword, date_from, date_to, price_from_to, nicdark_price_from, nicdark_price_to
- Affected:
- 2.0 – 3.8
- Fix:
- No patched version reported
Love Travel [lovetravel] < 2.0
unknown
An Unauthenticated Reflected XSS & XFS vulnerabilities was discovered in the Love Travel theme for WordPress, affected versions: 1.0-1.9. Vulnerable parameters: nd_travel_archive_form_keyword, nd_travel_typology_slug. The issue was fixed due to a code rewrite of the theme.
- Affected:
- up to 2.0
- Fixed in:
- 2.0
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database