The WPMovieLibrary WordPress plugin through version 2.1.4.8 contains a reflected cross-site scripting vulnerability. The plugin does not properly sanitize and escape the 'order' parameter in the import page before outputting it back, which could allow attackers to execute arbitrary JavaScript code in an administrator's browser context.
id: CVE-2024-13624
info:
name: WordPress WPMovieLibrary Plugin <= 2.1.4.8 - Cross-Site Scripting
...