WordPress Nextend Facebook Connect 1.5.4 Cross Site Scripting

WordPress NextEnd Connect plugin version 1.5.4 suffers from a cross site scripting vulnerability.