The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecting them into HTML attributes on its public pages, leading to reflected Cross-Site Scripting that can be triggered against any visitor, including a logged-in administrator.
https://wpscan.com/vulnerability/a1243ff3-3f0e-4068-a716-722e7cf4856b/