CVE-2021-24300: PickPlugins Product Slider for WooCommerce < 1.13.22 - Reflected Cross-Site Scripting (XSS)
The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issue
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-24300.
What is the title of the vulnerability?
The title of the vulnerability is 'The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin...' (truncated for display).
What is the description of the vulnerability?
The description of the vulnerability is 'The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitise the keyword GET parameter, leading to reflected Cross-Site Scripting issue.'
What is the severity of CVE-2021-24300?
The severity of CVE-2021-24300 is medium with a CVSS score of 6.1.
How can I fix the vulnerability in PickPlugins Product Slider for WooCommerce WordPress plugin?
To fix the vulnerability, update the PickPlugins Product Slider for WooCommerce WordPress plugin to version 1.13.22 or later.