Vendor
The OMGF WordPress plugin is vulnerable to stored Cross-Site Scripting via the 's' parameter in comments-atom feeds, allowing unauthenticated script injection in environments where web servers permit MIME-sniffing.