The CarSpot theme prior to 2.1.7 for WordPress has stored XSS via the Phone Number field.
carspot project carspot