WordPress Symposium through 15.8.1 contains a reflected cross-site scripting vulnerability via the wp-content/plugins/wp-symposium/get_album_item.php?size parameter which allows an attacker to steal cookie-based authentication credentials and launch other attacks.
View the template here CVE-2015-9414.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2015-9414