The WP Plugin Info Card plugin for WordPress has a security issue that allows unauthorized users to inject harmful code into web pages. This can happen in versions up to and including 5.2.5 because the plugin does not properly filter and protect user input and output. As a result, contributors or higher-level users can add malicious scripts to pages, which will be executed whenever someone visits those pages.