The plugin does not sanitise and escape some parameters, which could allow users with a role as low as author to perform Cross-Site Scripting attacks
XSS
Ngo Van Thien
No
2021-12-20 (about 1 years ago)
2022-04-18 (about 1 years ago)
2022-04-19 (about 1 years ago)