The FunnelKit WordPress plugin before 3.12.0.1 does not sanitize user input before echoing it back in some of its checkout-related AJAX actions, allowing attackers to conduct reflected XSS attacks against logged-in users.
https://wpscan.com/vulnerability/c7536b0c-3bce-449d-937e-b0195990110a/