Skip to content

Known CVE

WordPress eCommerce Product Catalog <3.0.39 - Cross-Site Scripting

WordPress eCommerce Product Catalog plugin before 3.0.39 contains a cross-site scripting vulnerability. The plugin does not escape the ic-settings-search parameter before outputting it back in the page in an attribute. This can allow an attacker to steal cookie-based authentication credentials and launch other attacks.

CVE-2021-24875

Medium2021CVSS 6.1CWE-79

cve2021 · wp · authenticated · wpscan · ecommerce-product-catalog · xss · wordpress · wp-plugin

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website