Easy Social Feed < 6.2.7 is susceptible to reflected cross-site scripting because the plugin does not sanitize and escape a parameter before outputting it back in an admin dashboard page, leading to it being executed in the context of a logged admin or editor.
id: CVE-2021-25120
info:
name: Easy Social Feed < 6.2.7 - Cross-Site Scripting
author: dhiyanes
...