The events-manager plugin prior to 5.1.7 for WordPress has XSS via JSON call links.
wp-events-plugin events manager