The Prime Slider plugin for WordPress has a security issue that could allow hackers to add harmful code to certain pages. This can happen in all versions up to 3.13.2 and is caused by not properly filtering and protecting the ‘settings[‘title_tags’]’ attribute of the Mercury widget. This could affect users with contributor-level access or higher.