Medium severity6.1NVD Advisory· Published Mar 14, 2022· Updated Jun 17, 2026
CVE-2021-24940
CVE-2021-24940
Description
The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an attribute in the admin dashboard, which could lead to a Reflected Cross-Site Scripting issue
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Persian Woocommerce/Persian Woocommerce WordPress plugindescription
- Range: <=5.8.0
- cpe:2.3:a:woocommerce:persian-woocommerce:*:*:*:*:*:wordpress:*:*Range: <=5.8.0
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/1980c5ca-447d-4875-b542-9212cc7ff77fnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.