6.1
CVSSv3

CVE-2024-13406

CVSSv4: NA | CVSSv3: 6.1 | CVSSv2: NA | VMScore: 710 | EPSS: 0.00046 | KEV: Not Included
Published: 22/01/2025 Updated: 22/01/2025

Vulnerability Summary

Reflected XSS in Google Merchant Center Plugin Up to 3.0.11

The XML for Google Merchant Center plugin for WordPress, up to version 3.0.11, has a vulnerability. This is a Reflected Cross-Site Scripting issue via the 'feed_id' parameter. The problem is because of not enough input sanitization and output escaping. Unauthenticated attackers can inject harmful scripts. These scripts run if they can get a user to click on a certain link.

Vulnerable Product Search on Vulmon Subscribe to Product

icopydoc xml for google merchant center