The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.

Source