The Skins for Contact Form 7 WordPress plugin before 2.5.1 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
https://wpscan.com/vulnerability/e2185887-3e53-4089-aa3f-981c944ee0bb