The YITH WooCommerce Ajax Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'queryString' parameter in the REST API endpoint /ywcas/v1/register in versions up to, and including, 2.4.0 due to insufficient input sanitization and output escaping.
id: CVE-2024-4455
info:
name: YITH WooCommerce Ajax Search <= 2.4.0 - Cross-Site Scripting
auth
...