WordPress WooCommerce Google Shopping < 1.2.4 - Cross-Site Scripting
WordPress WooCommerce Google Shopping < 1.2.4 is susceptible to cross-site scripting because the plugin does not sanitize or escape the search GET parameter before outputting it back in the page and executing it in a logged in admin context.