The Jetpack plugin prior to 3.4.3 for WordPress has XSS via add_query_arg() and remove_query_arg().
automattic jetpack