Robuta

https://wpscan.com/submit/ Submit a Vulnerability | WPScan Admins and editors are allowed to use JS in posts/pages/comments/etc, so the unfiltered_html capability should be disallowed when testing for Stored XSS using... submit a vulnerabilitywpscan