The mtouch-quiz plugin prior to 3.1.3 for WordPress has XSS via the quiz parameter during a Quiz Manage operation.
mtouch quiz project mtouch quiz