The Master Addons plugin for WordPress has a vulnerability that allows attackers to inject harmful code into pages. This can happen when a user with contributor-level access or higher uses the plugin’s Tooltip feature. The issue is present in all versions up to 2.0.6.7 and is caused by the plugin not properly filtering out dangerous code from user-supplied information.