Share
## https://sploitus.com/exploit?id=WPEX-ID:10395
Login as an editor or admin, then add/edit a business and set the phone number as "><img src onerror=alert(`XSS`)>

The payload will then be executed in the business list dashboard.

Other affected fields: Country, State, Social media url, E-mail, City, Zip, Address, Location and Hours