CVE-2021-24300
MEDIUM NUCLEIProduct Slider for WooCommerce < 1.13.22 - Reflected XSS via Slider Import
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-24300. PoCs published by 0xB9. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in the WordPress Plugin Product Slider for WooCommerce 1.13.21. The vulnerability is triggered via the 'keyword' parameter in the import_layouts page, allowing arbitrary JavaScript execution.
Description
The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issue
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in the WordPress Plugin Product Slider for WooCommerce 1.13.21. The vulnerability is triggered via the 'keyword' parameter in the import_layouts page, allowing arbitrary JavaScript execution.
Nuclei Templates (1)
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N