WordPress WHMCS Bridge plugin before 6.4b contains a reflected cross-site scripting vulnerability. It does not sanitize and escape the error parameter before outputting it back in the admin dashboard.
View the template here CVE-2021-25112.yaml
References:
https://github.com/ARPSyndicate/kenzer-templates