The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users with the Administrator role and above to perform Stored Cross-Site Scripting attacks.
https://wpscan.com/vulnerability/263e7dc0-61bb-468e-9e15-a6b6789923f4/