WordPress Simple Membership plugin before 4.1.1 contains a reflected cross-site scripting vulnerability. It does not properly sanitize and escape parameters before outputting them back in AJAX actions.
View the template here CVE-2022-1724.yaml
References:
https://github.com/ARPSyndicate/cvemon