WordPress Permalink Manager Lite and Pro plugins before 2.2.15 contain a reflected cross-site scripting vulnerability. They do not sanitize and escape query parameters before outputting them back in the debug page.
View the template here CVE-2022-0201.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2022-0201