The Participants Database plugin before 1.7.5.10 for WordPress has XSS.
https://www.exploit-db.com/exploits/42618/
https://wordpress.org/plugins/participants-database/#developers
https://limbenjamin.com/articles/cve-2017-14126-participants-database-xss.html