WordPress White Label CMS plugin before 2.2.9 contains a reflected cross-site scripting vulnerability. It does not sanitize and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing.
id: CVE-2022-0422
info:
name: WordPress White Label CMS <2.2.9 - Cross-Site Scripting
author: r
...