WordPress Supsystic Contact Form plugin before 1.7.15 contains a cross-site scripting vulnerability. It does not sanitize the tab parameter of its options page before outputting it in an attribute.
id: CVE-2021-24276
info:
name: WordPress Supsystic Contact Form <1.7.15 - Cross-Site Scripting
...