First published: Mon May 24 2021(Updated: )
The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issue
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
PickPlugins Product Slider for WooCommerce | <1.13.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-24300.
The title of the vulnerability is 'The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin...' (truncated for display).
The description of the vulnerability is 'The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitise the keyword GET parameter, leading to reflected Cross-Site Scripting issue.'
The severity of CVE-2021-24300 is medium with a CVSS score of 6.1.
To fix the vulnerability, update the PickPlugins Product Slider for WooCommerce WordPress plugin to version 1.13.22 or later.