WordPress WHMCS Bridge plugin before 6.4b contains a reflected cross-site scripting vulnerability. It does not sanitize and escape the error parameter before outputting it back in the admin dashboard.
id: CVE-2021-25112
info:
name: WordPress WHMCS Bridge <6.4b - Cross-Site Scripting
author: dhiy
...