WordPress GTranslate plugin before 2.8.52 contains an unauthenticated reflected cross-site scripting vulnerability via a crafted link. This requires use of the hreflang tags feature within a sub-domain or sub-directory paid option.
View the template here CVE-2020-11930.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2020-11930