The New User Approve plugin for WordPress is vulnerable to a type of attack called Reflected Cross-Site Scripting. This type of attack can occur when a malicious link is clicked by a user. If this link is clicked, it can allow an attacker to inject web scripts into pages, which will then be executed. This vulnerability exists in the versions up to and including 2.4 of the plugin and is caused by the lack of appropriate escaping of the URL.