The wp-all-import plugin before 3.4.6 for WordPress has XSS.
Published August 20, 2019.
Soflyy WP All Import