WordPress Domain Check plugin before 1.0.17 contains a reflected cross-site scripting vulnerability. It does not sanitize and escape the domain parameter before outputting it back in the page.
View the template here CVE-2021-24926.yaml
References:
https://wpscan.com/vulnerability/8cc7cbbd-f74f-4f30-9483-573641fea733