The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg.
No PoCs from references.
- https://github.com/20142995/nuclei-templates
- https://github.com/ARPSyndicate/cvemon