WordPress Qards through 2017-10-11 contains a cross-site scripting vulnerability via a remote document specified in the URL parameter to html2canvasproxy.php.
id: CVE-2017-18598
info:
name: WordPress Qards - Cross-Site Scripting
author: pussycat0x
seve
...