WordPress Copyright Proof plugin 4.16 and prior contains a cross-site scripting vulnerability. It does not sanitize and escape a parameter before outputting it back via an AJAX action available to both unauthenticated and authenticated users when a specific setting is enabled.
id: CVE-2022-1906
info:
name: WordPress Copyright Proof <=4.16 - Cross-Site-Scripting
author: r
...