Share
## https://sploitus.com/exploit?id=WPEX-ID:426EAFB1-0261-4E7E-8C70-75BF4C476F18
As an admin (and with the UNFILTERED_HTML disallowed), add a quote with the following payload in the "First Name", "Last Name", "Address", "City", and "Additional Details" fields: <script>alert(/XSS/)</script>

View the 'All Quotes" list to trigger the XSS