The Popup Maker plugin for WordPress has a security issue where malicious code can be injected through a parameter called ‘popupID’. This can happen in versions 1.20.4 and below because the plugin does not properly clean and protect the input and output. This means that people with Contributor-level access or higher can add harmful scripts to pages that will run whenever someone views that page.