CVE-2021-24300 EXPLOIT
6.1
MEDIUM · CVSS 3.1 · EPSS 10.6% (pctl 96)
Patch early
A public exploit exists.
Description
The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issue
Scoring
| CVSS | 6.1 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 10.59% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2021-05-24 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| pickplugins | product slider for woocommerce |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | WordPress Plugin Product Slider for WooCommerce 1.13.21 - Cross Site Scripting (XSS) | 2022-02-02 |
References
→ the Explorer · watch your stack · NVD