The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitize and escapes some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
https://wpscan.com/vulnerability/ef5aa8a7-23a7-4ce0-bb09-d9c986386114