Reflected XSS in WordPress Plugin Admin Pages (blog.sucuri.net)
The administrative dashboard in WordPress is a pretty safe place: Only elevated users can access it. Exploiting a plugin’s admin panel would serve very little purpose here — an administrator[…]