The plugin does not escape some parameters before outputting them back in admin pages, leading to Reflected Cross-Site Scripting issues
https://example.com/wp-admin/admin.php?page=manage_students&course_id=1&student_id="><script>alert(/XSS/)</script>
2021-08-16 (about 9 months ago)
2021-08-16 (about 9 months ago)
2021-08-16 (about 9 months ago)