The plugin does not sanitise and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
id: CVE-2023-0099
info:
name: Simple URLs < 115 - Cross Site Scripting
author: r3Y3r53
severi
...