The Events Manager plugin before 5.8.1.2 for WordPress allows XSS via the events-manager.js mapTitle parameter in the Google Maps miniature.
- https://www.gubello.me/blog/events-manager-authenticated-stored-xss/
- https://www.youtube.com/watch?v=40d7uXl36O4
- https://github.com/20142995/nuclei-templates