The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages.
- https://wpvulndb.com/vulnerabilities/9736
- https://github.com/20142995/nuclei-templates
- https://github.com/ARPSyndicate/cvemon