The WC Marketplace plugin for WordPress has a security issue where malicious scripts can be injected into pages if an attacker is able to trick a user into clicking on a link. This can happen in versions up to 4.1.17 due to inadequate protection against harmful inputs.