WordPress Qards through 2017-10-11 contains a cross-site scripting vulnerability via a remote document specified in the URL parameter to html2canvasproxy.php.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view