CVE-2021-24297
The Goto WordPress theme before 2.1 did not properly sanitize the formvalue JSON POST parameter in its tl_filter AJAX action, leading to an unauthenticated Reflected Cross-site Scripting (XSS) vulnerability.
Date published : 2021-05-24
https://wpscan.com/vulnerability/a64a3b2e-7924-47aa-96e8-3aa02a6cdccc