CVE-2026-33209 | avo-hq avo up to 3.30.2 return_to cross site scripting (GHSA-762r-27w2-q22j)
A vulnerability was found in avo-hq avo up to 3.30.2. It has been classified as problematic. This issue affects some unknown processing. The manipulation of the argument return_to leads to cross site scripting.
This vulnerability is documented as CVE-2026-33209. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.