# Check & Log Email Check & Log Email -> Settings -> Encoding -> check the 'Email Encoder' box and click Save As Unauthenticated user add a comment to any post with the following content: Log in as the admin user and navigate to the comment moderation '/wp-admin/edit-comments.php' and observe that the JavaScript payload is executed. ``` ## 参考链接 - URL: https://sec.stealthcopter.com/regexss/ ## 其他信息 - **原始研究员**:Matthew Rollings - **提交者**:Matthew Rollings - **提交者网站**:https://sec.stealthcopter.com - **提交者 Twitter**:@stealthcopter - **已验证**:是 - **WPVDB ID**:97908c15-6e7a-4242-8c6f-66c8b804364c - **公开日期**:2026-04-07