The all-in-one-wp-security-and-firewall plugin prior to 3.9.8 for WordPress has XSS in the unlock request feature.
tipsandtricks-hq all in one wp security \\& firewall