The quotes-collection plugin prior to 2.0.6 for WordPress has XSS via the wp-admin/admin.php?page=quotes-collection page parameter.
quotes collection project quotes collection