The WOOF WordPress plugin does not sanitize or escape the woof_redraw_elements parameter before reflecting it back in an admin page, leading to a reflected cross-site scripting.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view