Description
An attacker can control one or more parameter values of a sensitive HTML tag (e.g. link href). In some conditions this can cause security issues such as XSS (cross-site scripting).
Remediation
Your script should properly sanitize user input. Do not allow user-input to fully control important parameter tag values.
References
OWASP - Cross Site Scripting (XSS)
CWE-829: Inclusion of Functionality from Untrusted Control Sphere
Related Vulnerabilities
WordPress Plugin WebARX Cross-Site Scripting (1.3.0)
WordPress Plugin s2member Secure File Browser Cross-Site Scripting (0.4.16)
WordPress Plugin Rimons Twitter Widget Cross-Site Scripting (1.2.4)
WordPress Plugin Fast Secure Contact Form Cross-Site Scripting (4.0.37)
WordPress Plugin WP Elegant Testimonial Cross-Site Scripting (1.1.6)