The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL parameters, leading to Reflected Cross-Site Scripting.CreditsAlex SanfordWPScanReferenceshttps://wpscan.com/vulnerability/1187e041-3be2-4613-8d56-c2394fcc75fb