Description
This script is possibly vulnerable to client side template injection attacks.
Client side template injection is a vulnerability similar to cross site scripting that allows an attacker to send malicious code (usually in the form of JavaScript) to another user.
The injected code is executed by the client side templating and allows the attacker to take control of the victim's browser.
Remediation
Apply context-dependent encoding and/or validation to user input rendered on a page
References
Related Vulnerabilities
WordPress Plugin WP Whois Domain Cross-Site Scripting (1.0.0)
WordPress 2.1.1 Cross-Site Scripting Vulnerability (2.1.1)
WordPress Plugin WP Statistics Cross-Site Scripting (12.0.9)
WordPress Plugin Grid Gallery-Photo Image Grid Gallery Cross-Site Scripting (1.2.4)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Cross-Site Scripting (4.1.9)