WordPress WooCommerce before 1.13.22 contains a reflected cross-site scripting vulnerability via the slider import search feature because it does not properly sanitize the keyword GET parameter.
id: CVE-2021-24300
info:
name: WordPress WooCommerce <1.13.22 - Cross-Site Scripting
author: cc
...