Beta

Report

Goto <= 2.0 is vulnerable to Unauthenticated Blind SQL Injection (SQLi) vulnerability

Unauthenticated
Published
2021-04-27

The Goto - Tour & Travel WordPress Theme WordPress theme before 2.1 did not sanitise, validate of escape the keywords GET parameter from its listing page before using it in a SQL statement, leading to an Unauthenticated SQL injection issue.

CVSS

Score:9.8

Severity:Critical

Version: 2.0

There is a patch available in v2.1 and we strongly recommend you update to this version as soon as possible.