WordPress Supsystic Contact Form plugin before 1.7.15 contains a cross-site scripting vulnerability. It does not sanitize the tab parameter of its options page before outputting it in an attribute.
View the template here CVE-2021-24276.yaml
References:
https://github.com/ARPSyndicate/cvemon