The Blog2Social plugin prior to 5.0.3 for WordPress allows wp-admin/admin.php?page=blog2social-ship XSS.
adenion blog2social