The MOLIE WordPress plugin through 0.5 does not escape the course_id parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting issueCreditsJeremie AmsellemReferenceshttps://wpscan.com/vulnerability/dbe2c6ca-d2f1-40a2-83d5-4623c22d4d61