WordPress Plugin uCan Post is prone to multiple HTML injection vulnerabilities because it fails to properly sanitize user-supplied input. Attacker supplied HTML and script code could be executed in the context of the affected site, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user; other attacks may also be possible. WordPress Plugin uCan Post version 1.0.09 is vulnerable; other versions may also be affected.
Edit the source code to ensure that input is properly sanitised or disable the plugin until a fix is available
WordPress Plugin Gwolle Guestbook Remote File Inclusion (1.5.3)
WordPress Plugin Images to WebP Multiple Vulnerabilities (1.8)
WordPress Plugin Age Gate Cross-Site Scripting (2.16.3)
WordPress Plugin Comments-wpDiscuz Cross-Site Scripting (7.3.1)