The woo-variation-gallery plugin before 1.1.29 for WordPress has XSS.

%d bloggers like this: