WordPress Copyright Proof plugin 4.16 and prior contains a cross-site scripting vulnerability. It does not sanitize and escape a parameter before outputting it back via an AJAX action available to both unauthenticated and authenticated users when a specific setting is enabled.
View the template here CVE-2022-1906.yaml
References:
https://github.com/ARPSyndicate/kenzer-templates