WordPress Plugin Ultimate Product Catalogue 5.8.2 Stored XSS via price
Vulnerability Description
Ultimate Product Catalogue 5.8.2 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the price parameter. Attackers can submit POST requests to post.php with HTML/JavaScript payloads in the price field to execute arbitrary code when the product is viewed.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-47924
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Murat DEMIRCI (@murat0x7)
References
More from Etoilewebdesign
View All →Affected Vendor
Etoilewebdesign
View all reports →