WordPress White Label CMS plugin before 2.2.9 contains a reflected cross-site scripting vulnerability. It does not sanitize and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing.
View the template here CVE-2022-0422.yaml
References:
https://github.com/ARPSyndicate/cvemon