The Bit Assist plugin for WordPress has been found to have a security vulnerability in versions 1.1.8 and below. This vulnerability could allow someone with administrator-level permissions to inject malicious code into pages that can be executed by anyone who views the page. This vulnerability is only present when the website uses a multi-site installation and has disabled the unfiltered_html setting.