PickPlugins Product Slider for WooCommerce < 1.13.22 - Reflected Cross-Site Scripting (XSS)
43Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 11%
from disclosure to weapon254 days
Published on NVDMay 24
1st PoC+254d
exploitation probability
11%top 5% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issue
Affected products
PickPlugins · PickPlugins Product Slider for WooCommercepublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/50704unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.