WordPress Awin Data Feed plugin 1.6 and prior contains a cross-site scripting vulnerability. It does not sanitize and escape a parameter before outputting it back via an AJAX action, available to both unauthenticated and authenticated users.
id: CVE-2022-1937
info:
name: WordPress Awin Data Feed <=1.6 - Cross-Site Scripting
author: Aki
...