includes/theme-functions.php in the OneTone theme through 3.0.6 for WordPress has multiple stored XSS issues.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://blog.nintechnet.com/unauthenticated-stored-xss-vulnerability-in-wordpress-onetone-theme-unpatched/ | third party advisory exploit |