The WPPizza WordPress plugin is not secure in versions up to 3.18.2. Attackers who are not authenticated can inject malicious web scripts into pages that are executed when tricked users perform an action, such as clicking a link. The vulnerability is due to inadequate input sanitization and output escaping.