The WOOF WordPress plugin does not sanitize or escape the woof_redraw_elements parameter before reflecting it back in an admin page, leading to a reflected cross-site scripting.
id: CVE-2021-25085
info:
name: WOOF WordPress plugin - Cross-Site Scripting
author: Maximus Dec
...