疑似Oday
The PublishPress Capabilities plugin for WordPress before 2.3.3 does not escape a form action URL before outputting it back in an attribute, leading to Reflected Cross-Site Scripting (XSS).
id: wp-publishpress-capabilities-xss
info:
name: PublishPress Capabilities < 2.3.3 - Cross-Site S
...