What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Product Slider for WooCommerce woocommerce-products-slider allows Reflected XSS.This issue affects Product Slider for WooCommerce: from n/a through <= 1.13.50.
Explanation of Vulnerability in Simple Terms
02Summary
Product Slider for WooCommerce versions up to 1.13.50 contain a stored cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts into the plugin's settings or content fields. When site administrators or other users view the affected pages, the injected code executes in their browsers, potentially allowing the attacker to steal session tokens, modify site content, or perform actions on their behalf.
What an attacker can do
03Attacker Capabilities
Inject malicious JavaScript that executes when site users view affected pages, potentially stealing credentials or modifying content.
Potential impact on your site
04Site Impact
Attackers can compromise admin accounts, deface your site, or redirect visitors to malicious sites without your knowledge.
Conditions required to exploit
05Prerequisites
User interaction required: a site admin or user must view a page containing the attacker's injected payload. No authentication needed to inject the payload.
Key dates
06Disclosure timeline
September 15, 2024
CVE published
April 28, 2026
Record updated