Share
## https://sploitus.com/exploit?id=WPEX-ID:689D2AC5-38D4-4791-B35C-A0E34EF73D57
Put the following payload in the Google Analytics ID settings of the plugin (/wp-admin/customize.php?autofocus[section]=vdz_google_analytics_section), then access the frontend to trigger the XSS: ');alert('XSS