The plugin Easy Testimonials for WordPress, up to and including version 3.8, contains a security vulnerability that could allow unauthenticated attackers to inject malicious code onto webpages. This could be done by tricking a user into clicking a link or performing some other action.