The plugin does not sanitise and escape a parameter before outputting it back in a page accessible to contributors and above, leading to a Reflected Cross-Site Scripting
2022-05-04 (about 9 months ago)
2022-05-21 (about 8 months ago)
2022-05-21 (about 8 months ago)