WordPress Simple Membership plugin before 4.1.1 contains a reflected cross-site scripting vulnerability. It does not properly sanitize and escape parameters before outputting them back in AJAX actions.
id: CVE-2022-1724
info:
name: WordPress Simple Membership <4.1.1 - Cross-Site Scripting
author:
...