The eaSYNC plugin for WordPress is a security risk in versions up to 1.3.7. Attackers can insert malicious web scripts into pages if they can trick a user into clicking on a link. This is because the plugin does not properly block or remove potentially dangerous input or code.