The simple-mail-address-encoder plugin before 1.7 for WordPress has reflected XSS.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected