The DrawBlog WordPress plugin through 0.90 does not sanitise or validate some of its settings before outputting them back in the page, leading to an authenticated stored Cross-Site Scripting issueCreditsABISHEIK MReferenceshttps://wpscan.com/vulnerability/5fd2246a-fbd9-4f2a-8b0b-a64c3f91157c