WordPress 4.2.1 XSS / Code Execution

Exploit that uses a WordPress cross site scripting flaw to execute code as the administrator.