Description
WordPress Theme OneTone is prone to an unauthenticated Stored Cross-Site Scripting vulnerability in version 3.0.6 and below.
Remediation
Remove the theme from your WordPress installation.
References
Vulnerability Information at wpvulndb.com
Unauthenticated stored XSS vulnerability in WordPress OneTone theme
Related Vulnerabilities
WordPress Plugin Broken Link Checker Cross-Site Scripting (1.10.4)
WordPress Plugin WooCommerce Cross-Site Scripting (2.6.8)
WordPress Plugin HDW WordPress Video Gallery Multiple Cross-Site Scripting Vulnerabilities (1.2)
WordPress Plugin WP Socializer-Simple & Easy Social Media Share Icons Cross-Site Scripting (7.2)
WordPress Plugin WP-VR-view-Add Photo Sphere, 360 video to WordPress Cross-Site Scripting (1.6)