WordPress Add Shortcodes Actions And Filters plugin <= 2.0.9 管理员后台出现XXS漏洞

POC如下:
Dashboard—->Tools—->Shortcodes,Actions and Filters—->Add New —->fill name with “> and then fill any value with others. and then click “save” botton after done that,there would be the stored xxs
主要还是因为一些特殊字符如>等没有过滤从而导致了存储型的XXS