The insert-php (aka Woody ad snippets) plugin before 2.2.8 for WordPress allows authenticated XSS via the winp_item parameter.Referenceshttps://wordpress.org/plugins/insert-php/#developershttps://generaleg0x01.com/2019/09/13/xss-woody/https://wpvulndb.com/vulnerabilities/9880