WordPress Supsystic Contact Form plugin before 1.7.15 contains a cross-site scripting vulnerability. It does not sanitize the tab parameter of its options page before outputting it in an attribute.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view