S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24235 Scanner

CVE-2021-24235 scanner - Cross-Site Scripting (XSS) vulnerability in Goto theme for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24235
6.1
CVSS

The Goto WordPress theme before 2.0 does not sanitise the keywords and start_date GET parameter on its Tour List page, leading to an unauthenticated reflected Cross-Site Scripting issue.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Goto
AFFECTED< 2.0SAFE ✓≥ 2.0
Updated Aug 21, 2026View on NVD →
Detail

The Goto WordPress theme is a popular theme used for travel agencies and tour operators. It is designed to showcase different tour packages, destinations, and activities, as well as allow visitors to book their trips directly on the website. This theme offers a range of customizable features, including unique layouts, slider options, and booking calendars, making it a valuable tool for businesses in this niche.

However, the Goto WordPress theme version 2.0 was recently found to have a vulnerability that could put websites at risk of a Cross-Site Scripting (XSS) attack. This vulnerability was designated CVE-2021-24235 and is a result of the theme's failure to sanitize the keywords and start_date GET parameters on its Tour List page. This means that an attacker could send a specifically crafted URL to a site visitor, which would then execute arbitrary code when opened.

If this vulnerability is exploited, it could lead to a range of negative consequences for businesses using the Goto WordPress theme, including the theft of sensitive information, such as user credentials, payment details, or personal data. It could also result in a website being defaced, causing damage to the business's reputation and potentially leading to financial losses.

Finally, it's worth noting that s4e.io's platform provides a range of pro features, including vulnerability scanning, that make it easy for businesses to detect and fix vulnerabilities in their digital assets. By using this platform, businesses can ensure that their websites are secure and protected against potential attacks, including those that exploit the CVE-2021-24235 vulnerability in the Goto WordPress theme.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners using the Goto WordPress theme should follow these precautions:

  • Update the theme to version 2.1 or higher, which includes a patch for the CVE-2021-24235 vulnerability.
  • Use a web application firewall (WAF) to block malicious traffic.
  • Regularly scan the website for vulnerabilities and apply patches and updates as needed.
  • Educate users on safe browsing habits and encourage the use of strong, unique passwords.
  • Monitor log files and network traffic for signs of an attack.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24235 scanner - Cross-Site Scripting (XSS) vulnerability in Goto theme for WordPress | S4E