The Absolute Reviews plugin for WordPress has a security issue where hackers can insert harmful code into the ‘Name’ field of a custom post. This can happen in versions up to 1.1.3 and allows attackers with Contributor-level access or higher to run their code on any page that is opened by a user.