WordPress JH 404 Logger plugin through 1.1 contains a cross-site scripting vulnerability. Referer and path of 404 pages are not properly sanitized when they are output in the WordPress dashboard, which can lead to executing arbitrary JavaScript code.
id: CVE-2021-24176
info:
name: WordPress JH 404 Logger <=1.1 - Cross-Site Scripting
author: Gan
...