Description
An attacker can control one or more parameter values of a sensitive HTML tag (e.g. link href). In some conditions this can cause security issues such as XSS (cross-site scripting).
Remediation
Your script should properly sanitize user input. Do not allow user-input to fully control important parameter tag values.
References
OWASP - Cross Site Scripting (XSS)
CWE-829: Inclusion of Functionality from Untrusted Control Sphere
Related Vulnerabilities
WordPress Plugin WP Forum Server Cross-Site Scripting and SQL Injection Vulnerabilities (1.7.3)
WordPress Plugin Weekly Schedule Cross-Site Scripting (3.4.2)
WordPress Plugin Database Sync Cross-Site Scripting (0.4)
WordPress Plugin Watu Quiz Cross-Site Scripting (3.3.8.1)
WordPress Plugin Slider Hero with Animation, Video Background Cross-Site Scripting (8.4.3)