WordPress File Manager plugin before 3.0 is vulnerable to authenticated reflected cross-site scripting (XSS) via the lang parameter in the admin dashboard. The parameter is directly echoed into a JavaScript context without proper sanitization.
id: CVE-2018-16363
info:
name: WordPress File Manager < 3.0 - Cross-Site Scripting
author: Shiv
...