Stripe Add-on for iThemes Exchange prior to 1.2.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
ithemes stripe