The plugins do not escape some URLs and parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting
XSS
WPScan
Yes
2022-12-05 (about 1 months ago)