The plugin called wp-mpdf for WordPress has a security issue that allows attackers to inject harmful scripts onto web pages. This can happen if a user is tricked into clicking on a link. The vulnerability is present in versions up to 3.7.1 and is caused by not properly filtering and escaping input.