The WP Mail Logging plugin for WordPress has a security vulnerability which could allow an attacker to inject malicious code into pages that are accessed by other users. This vulnerability affects versions up to and including 1.8.2. It is caused by the plugin not properly sanitizing and escaping user input, making it possible for attackers to inject arbitrary web scripts.