Loading
The Store Toolkit for WooCommerce WordPress plugin before 2.3.2 does not sanitise and escape the tab parameter before outputting it back in an admin page in an error message, leading to a Reflected Cross-Site Scripting
Use CWE-79, Visser vendor hub and Store Toolkit For Woocommerce product page to widen CVE-2021-25077 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2016-10923 and CVE-2016-10922 for nearby disclosures in the same product family.