## https://sploitus.com/exploit?id=WPEX-ID:7C87FCD2-6FFD-4285-BBF5-36EFEA70B620
1. Go to https://example.com/wp-admin/admin.php?page=font-farsi-custom-font
2. In the first field, add `"><script>alert(32)</script>`
3. Click "Save Changes" and see the XSS
Note: Other fields are likely vulnerable