CVE-2021-24875: eCommerce Product Catalog for WordPress < 3.0.39 - Reflected Cross-Site Scripting
Published Nov 23, 2021
·Updated
The eCommerce Product Catalog Plugin for WordPress plugin before 3.0.39 does not escape the ic-settings-search parameter before outputting it back in the page in an attribute, leading to a Reflected Cross-Site Scripting issue
Affected Software
1 affected component
impleCode Ecommerce Product Catalog Wordpress<3.0.39
Event History
Nov 23, 2021
CVE Published
via MITRE·07:16 PM
Data Sourced
via MITRE·07:16 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-24875.
2
What is the severity of CVE-2021-24875?
CVE-2021-24875 has a severity of 6.1, which is considered medium.
3
What software is affected by CVE-2021-24875?
The eCommerce Product Catalog Plugin for WordPress plugin before version 3.0.39 is affected by CVE-2021-24875.
4
What is the CWE ID associated with CVE-2021-24875?
CVE-2021-24875 has a CWE ID of 79.
5
How can I fix the CVE-2021-24875 vulnerability?
To fix the CVE-2021-24875 vulnerability, update the eCommerce Product Catalog Plugin for WordPress plugin to version 3.0.39 or later.