The Event Manager for WooCommerce plugin for WordPress has a security issue in versions up to 4.2.5. This means that hackers with contributor-level access or higher can insert harmful web scripts into pages, which will then run whenever someone views the page.