WordPress AJAX Random Post 2.00 is vulnerable to reflected cross-site scripting.
View the template here CVE-2016-1000127.yaml
echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2016/CVE-2016-1000127.yaml
References: