AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-24974

MEDIUM · CVSS 5.4 EPSS 0.61%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-01-24 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-24974
Severity
MEDIUM
CVSS
5.4
EPSS
0.61%
WordPress

Original NVD Description

The Product Feed PRO for WooCommerce WordPress plugin before 11.0.7 does not have authorisation and CSRF check in some of its AJAX actions, allowing any authenticated users to call then, which could lead to Stored Cross-Site Scripting issue (which will be triggered in the admin dashboard) due to the lack of escaping.