The marketo-forms-and-tracking plugin up to and including 1.0.2 for WordPress allows wp-admin/admin.php?page=marketo_fat CSRF with resultant XSS.
hutchhouse marketo forms and tracking