The ad-inserter plugin prior to 1.5.3 for WordPress has CSRF with resultant XSS via wp-admin/options-general.php?page=ad-inserter.php.
ad inserter project ad inserter