Product
The BA Book Everything WordPress plugin contains a stored XSS vulnerability in the first_name parameter, allowing unauthenticated attackers to inject arbitrary scripts.