The Custom CSS, JS & PHP plugin for WordPress has a security issue in versions up to 2.4.1. This is because the plugin does not properly check for valid authorization when saving options. As a result, attackers who are not logged in can insert harmful code by tricking a site administrator into clicking on a link.