The AFI plugin for WordPress has a security issue called Reflected Cross-Site Scripting. This is caused by not properly protecting the URL in all versions up to 1.92.0. This could allow attackers to add harmful scripts to a page and potentially harm users if they are tricked into clicking on a link.