The Brafton plugin before 3.4.8 for WordPress has XSS via the wp-admin/admin.php?page=BraftonArticleLoader tab parameter to BraftonAdminPage.php.
id: CVE-2016-10973
info:
name: Brafton WordPress Plugin < 3.4.8 - Cross-Site Scripting
author:
...