WordPress Permalink Manager Lite and Pro plugins before 2.2.15 contain a reflected cross-site scripting vulnerability. They do not sanitize and escape query parameters before outputting them back in the debug page.
id: CVE-2022-0201
info:
name: WordPress Permalink Manager <2.2.15 - Cross-Site Scripting
author
...