peter bassill · operator
$ cve CVE-2021-24300 JSON

CVE-2021-24300 EXPLOIT

6.1
MEDIUM · CVSS 3.1 · EPSS 10.6% (pctl 96)

Patch early

A public exploit exists.

Description

The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issue

Scoring

CVSS6.1 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS10.59% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2021-05-24
Last modified2026-06-17

Affected (1)

VendorProduct
pickpluginsproduct slider for woocommerce

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD