The crayon-syntax-highlighter plugin prior to 2.8.4 for WordPress has multiple XSS issues via AJAX requests.
crayon syntax highlighter project crayon syntax highlighter