The wp-support-plus-responsive-ticket-system plugin prior to 9.1.2 for WordPress has HTML injection.
wpsupportplus wp support plus responsive ticket system