Sorry, in this case I am only the messenger. But I had a sneaking suspicion you where not aware of this. We run Wordfence on our site and got this message. Yesterday I did some digging myself but I also could’nt find any details, which would have been nice to determine the scope and if – in our specific case – there would have been a chance on data leakage. But nothing specific was posted only – that I could find, at least.
Looking in the code of the plugin – I am not a dev – I saw in the last version you already did sanitize the parameter. So I am also at a loss at this moment. Maybe reach out to Wordfence or the original poster to see what’s what?