Several fields in the plugin are vulnerable to stored XSS when using the payload: 

`<img src=x onerror=confirm(/XSS/)>`

Affected fields include Customizer fields:

- "Notification Bar -> Content" (view site on frontend to see XSS)
- "Logo -> Logo Link -> Edit Link -> Link Text" (view site in WP Admin to see XSS)

WP Adminify Settings:

- "Admin Columns > Post Types > Post > Title"
- "Admin Columns > Taxonomies > Category > Title"