Description
An attacker can control one or more parameter values of a sensitive HTML tag (e.g. link href). In some conditions this can cause security issues such as XSS (cross-site scripting).
Remediation
Your script should properly sanitize user input. Do not allow user-input to fully control important parameter tag values.
References
OWASP - Cross Site Scripting (XSS)
CWE-829: Inclusion of Functionality from Untrusted Control Sphere
Related Vulnerabilities
WordPress Plugin User Activity Log Multiple Cross-Site Scripting Vulnerabilities (1.4.6)
WordPress Plugin Htaccess by BestWebSoft Cross-Site Scripting (1.7.5)
WordPress Plugin Media Mirror Cross-Site Scripting (1.0.6)
WordPress Plugin BestSmallShopLite Cross-Site Scripting (1.0.1)
WordPress Plugin Abandoned Cart Lite for WooCommerce Cross-Site Scripting (5.1.3)