The Easy Code Snippets plugin for WordPress, up to and including version 1.0.2, has a security vulnerability called SQL Injection. This happens because the plugin does not properly protect the user’s input and the existing SQL query. This means that someone with administrator access or higher can add extra SQL queries to the existing ones, which can then be used to get private information from the database.