The Advanced Image Sitemap WordPress plugin through 1.2 does not sanitise and escape the PHP_SELF PHP variable before outputting it back in an attribute in an admin page, leading to Reflected Cross-Site Scripting.Creditsp7e4Referenceshttps://wpscan.com/vulnerability/31a5b138-3d9e-4cd6-b85c-d20406ab51bd