The events-manager plugin prior to 5.6 for WordPress has code injection.
wp-events-plugin events manager