The Countdown, Coming Soon, Maintenance WordPress plugin before 2.2.9 does not sanitize and escape the post parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
https://wpscan.com/vulnerability/6ec62eae-2072-4098-8f77-b22d61a89cbf