
WordPress Passster Plugin <= 4.2.18 is vulnerable to Cross Site Scripting (XSS)
Sink: According to the mechanism of WordPress Core, XSS is prevented in post content, but with this plugin, the content is encoded and then decoded when rendered, unintentionally creating an XSS vulnerability."

PoC: The base64 encoded payload is PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg==
