CVE-2017-1000033
WordPress Plugin Vospari Forms version < 1.4 is vulnerable to a reflected cross site scripting in the form submission resulting in javascript code execution in the context on the current user. Date published : 2017-07-13 https://cjc.im/advisories/0007/