The Special Text Boxes WordPress plugin before 5.9.110 does not sanitise or escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
https://wpscan.com/vulnerability/4a6b278a-4c11-4624-86bf-754212979643