The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape the 'filterType' parameter, leading to Reflected Cross-Site Scripting.
id: CVE-2023-2624
info:
name: KiviCare WordPress Plugin - Cross-Site Scripting
author: ritikcha
...