The WP Duplicate Page WordPress plugin before 1.3 does not sanitize and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.
https://wpscan.com/vulnerability/a11628e4-f47b-42d8-9c09-7536d49fce4c