The Firelight Lightbox tool for WordPress has a security issue where harmful code can be injected into posts. This can happen in versions 2.3.15 and below when the jQuery Metadata library is turned on. This means that someone with Contributor-level access or higher can insert their own code into a page and it will run whenever someone views that page.