Loading
The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in an admin page, leading to a Reflected Cross-Site Scripting
Use CWE-79, Pluginus vendor hub and Woocommerce Products Filter product page to widen CVE-2021-25085 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-11400 for nearby disclosures in the same product family.