WordPress eCommerce Product Catalog plugin before 3.0.39 contains a cross-site scripting vulnerability. The plugin does not escape the ic-settings-search parameter before outputting it back in the page in an attribute. This can allow an attacker to steal cookie-based authentication credentials and launch other attacks.
View the template here CVE-2021-24875.yaml
References:
https://wpscan.com/vulnerability/652efc4a-f931-4668-ae74-a58b288a5715