iThemes Exchange prior to 1.12.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
ithemes exchange