The breadcrumbs-by-menu plugin before 1.0.3 for WordPress has XSS.

%d bloggers like this: