The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10705
Reference (s):
- https://jetpack.com/2016/06/20/jetpack-4-0-4-bug-fixes/
- https://wpvulndb.com/vulnerabilities/8517

