The simple-membership plugin prior to 3.5.7 for WordPress has XSS.
simple-membership-plugin simple membership