The YITH WooCommerce Product Add-Ons plugin for WordPress has a security vulnerability that allows for Cross-Site Scripting. This means that attackers can insert harmful web scripts into pages, which will run whenever a user visits the affected page. This vulnerability affects versions up to 4.5.0 of the plugin and is due to inadequate protection of user input and output.