WordPress Embed Swagger plugin 1.0.0 and prior contains a reflected cross-site scripting vulnerability due to insufficient escaping/sanitization and validation via the url parameter found in the ~/swagger-iframe.php file, which allows attackers to inject arbitrary web scripts onto the page.
id: CVE-2022-0381
info:
name: WordPress Embed Swagger <=1.0.0 - Cross-Site Scripting
author: ed
...