WordPress WHMCS Bridge plugin before 6.4b contains a reflected cross-site scripting vulnerability. It does not sanitize and escape the error parameter before outputting it back in the admin dashboard.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view