The WordPress Pinterest Plugin for WordPress is a plugin that allows users to add Pinterest content to their WordPress website. Unfortunately, versions up to and including 1.6.1 of this plugin are vulnerable to a type of attack called Stored Cross-Site Scripting. This type of attack allows authenticated attackers who have contributor-level permissions (or higher) to inject malicious code into pages on the website. When a user visits one of these pages, the malicious code will be executed, potentially doing harm to the user’s computer.