Unauthenticated Cross Site Scripting (XSS) in CformsII <= 15.1.3 versions.
Update the WordPress CformsII Plugin to the latest available version (at least 15.1.4).