The Custom Field Suite plugin before 2.5.15 for WordPress has XSS for editors or admins.
https://wpvulndb.com/vulnerabilities/9273
https://wordpress.org/plugins/custom-field-suite/#developers
https://blog.reddy.io/2019/05/30/xss-injection-vulnerability-in-custom-field-suite-wordpress-plugin/