Calls to Action plugin before 2.5.1 for WordPress contains stored XSS caused by unsanitized input in open-tab parameter in wp-admin/edit.php and wp-cta-variation-id parameter in ab-testing-call-to-action-example/, letting remote attackers inject arbitrary web script or HTML, exploit requires sending crafted requests.
id: CVE-2015-8350
info:
name: WordPress Calls to Action <=2.4.3 - Authenticated Reflected XSS
a
...