The 404 to 301 plugin for WordPress had a security vulnerability in versions before 2.3.1. This vulnerability caused pages to be open to attack from unauthenticated attackers. These attackers could inject web scripts into pages, which would execute any time a user viewed the page. This was due to the plugin not properly filtering or protecting the ‘Referer’ and ‘User-Agent’ HTTP Headers.