EPSS
Percentile
21.2%
The plugin does not sanitise and escape some parameters (such as category_name, description, description_2 etc), which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks