The Drop Shadow Boxes plugin for WordPress has a security vulnerability in versions up to 1.7.10. This means that people with contributor-level permissions and above can inject malicious scripts into pages that will run when a user visits the page. This happens because the plugin does not properly sanitize user-supplied data or escape output.