.. / CVE-2021-24875

Exploit for WordPress eCommerce Product Catalog <3.0.39 - Cross-Site Scripting (CVE-2021-24875)

Description:

WordPress eCommerce Product Catalog plugin before 3.0.39 contains a cross-site scripting vulnerability. The plugin does not escape the ic-settings-search parameter before outputting it back in the page in an attribute. This can allow an attacker to steal cookie-based authentication credentials and launch other attacks.

Nuclei Template

View the template here CVE-2021-24875.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-24875.yaml
Copy

References:

https://wpscan.com/vulnerability/652efc4a-f931-4668-ae74-a58b288a5715
https://github.com/ARPSyndicate/cvemon
https://github.com/ARPSyndicate/kenzer-templates
https://nvd.nist.gov/vuln/detail/CVE-2021-24875