The DW Question & Answer plugin for WordPress is vulnerable to a type of security flaw known as Stored Cross-Site Scripting (XSS). This vulnerability affects versions 1.4.2.2 and earlier of the plugin. It happens when the plugin does not properly check the data it receives and doesn’t take precautions to protect against malicious code. This could allow an attacker to inject malicious code into a page that would then be executed when a user visits the page.