The settings page of the plugin did not properly sanitise the tab parameter before outputting it back, leading to a reflected Cross-Site Scripting issue.
View the template here CVE-2021-24286.yaml
References:
https://github.com/ARPSyndicate/cvemon