## https://sploitus.com/exploit?id=WPEX-ID:88745C9B-1C20-4004-89F6-D9EE223651F2
Several fields in the plugin are vulnerable to stored XSS when using the payload:
`<img src=x onerror=confirm(/XSS/)>`
Affected fields include Customizer fields:
- "Notification Bar -> Content" (view site on frontend to see XSS)
- "Logo -> Logo Link -> Edit Link -> Link Text" (view site in WP Admin to see XSS)
WP Adminify Settings:
- "Admin Columns > Post Types > Post > Title"
- "Admin Columns > Taxonomies > Category > Title"