The Blocksy Companion plugin for WordPress is not secure in versions up to 1.8.67 and can be exploited by attackers who have contributor-level permissions or higher. This vulnerability allows attackers to inject malicious web scripts into the pages which get executed when a user visits the page. This is caused by a lack of proper sanitization and escaping of user-supplied data in the blocksy_posts shortcode.