The plugin CO2ok: carbon offsetting for e-commerce is not safe to use in versions up to 1.0.9.21. Attackers can insert malicious code into the pages of this plugin. This code will then be executed by any user who accesses the affected page. This is because the plugin doesn’t properly clean and protect the data it receives or sends.