The method and share GET parameters of the Giveaway pages were not sanitised, validated or escaped before being output back in the pages, thus leading to reflected XSS
https://wpscan.com/vulnerability/30aebded-3eb3-4dda-90b5-12de5e622c91
https://codevigilant.com/disclosure/2021/wp-plugin-giveasap-xss/