The shortcode-factory plugin prior to 1.1.1 for WordPress has XSS via add_query_arg.
wpmadeeasy shortcode factory