WordPress WPQA plugin prior to 5.4 contains a reflected cross-site scripting vulnerability. It does not sanitize and escape a parameter on its reset password form.
id: CVE-2022-1597
info:
name: WordPress WPQA <5.4 - Cross-Site Scripting
author: veshraj
seve
...