The Simple File List WordPress plugin before 4.4.12 does not escape parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting
https://github.com/Live-Hack-CVE/CVE-2022-3062
https://wpscan.com/vulnerability/2e829bbe-1843-496d-a852-4150fa6d1f7a