The marketo-forms-and-tracking plugin through 1.0.2 for WordPress allows wp-admin/admin.php?page=marketo_fat CSRF with resultant XSS.
- https://wpvulndb.com/vulnerabilities/10031
- https://zeroauth.ltd/blog/
- https://github.com/20142995/nuclei-templates