The plugin does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting
XSS
Lucio Sá
No
2022-08-25 (about 5 months ago)
2022-09-15 (about 4 months ago)