The WC Marketplace plugin for WordPress is vulnerable to a type of malicious attack called Reflected Cross-Site Scripting. This type of attack can occur if someone is tricked into clicking on a link containing malicious code. Versions of the plugin before 3.8.4 are vulnerable due to not properly sanitizing input or escaping output.