CPE
The Contact Form by Supsystic WordPress plugin is vulnerable to unauthenticated Stored Cross-Site Scripting due to insufficient sanitization of X-Forwarded-For headers.