WordPress Cart66 Lite 1.5.4 Cross Site Scripting

WordPress Cart66 Lite plugin version 1.5.4 suffers from a cross site scripting vulnerability.