There is a lack of escaping of the meta keys and values in the_meta() function, which could lead to Cross-Site Scripting issue
XSS
John Blackbourn
Yes
2022-08-30 (about 6 months ago)