iThemes Mobile prior to 1.2.8 for WordPress has XSS via add_query_arg() and remove_query_arg().
ithemes mobile