WordPress WooCommerce before 1.13.22 contains a reflected cross-site scripting vulnerability via the slider import search feature because it does not properly sanitize the keyword GET parameter.
View the template here CVE-2021-24300.yaml
References:
https://github.com/ARPSyndicate/cvemon