The ultimate-member plugin before 2.0.52 for WordPress has XSS during an account upgrade.

Source