WordPress Simple Giveaways plugin before 2.36.2 contains a cross-site scripting vulnerability via the method and share GET parameters of the Giveaway pages, which are not sanitized, validated, or escaped before being output back in the pages.
id: CVE-2021-24298
info:
name: WordPress Simple Giveaways <2.36.2 - Cross-Site Scripting
author
...