WordPress eCommerce Product Catalog plugin before 3.0.39 contains a cross-site scripting vulnerability. The plugin does not escape the ic-settings-search parameter before outputting it back in the page in an attribute. This can allow an attacker to steal cookie-based authentication credentials and launch other attacks.
id: CVE-2021-24875
info:
name: WordPress eCommerce Product Catalog <3.0.39 - Cross-Site Scripting
...