Easy Social Feed < 6.2.7 is susceptible to reflected cross-site scripting because the plugin does not sanitize and escape a parameter before outputting it back in an admin dashboard page, leading to it being executed in the context of a logged admin or editor.
View the template here CVE-2021-25120.yaml
References:
https://github.com/ARPSyndicate/cvemon